Summary
Scripteen Free Image Hosting Script is prone to multiple SQL-injection vulnerabilities and to an authentication-bypass vulnerability.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database or to gain administrative access.
Scripteen Free Image Hosting Script 2.3 is vulnerable other versions
may also be affected.
References
Severity
Classification
-
CVE CVE-2009-2892 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Artmedic Kleinanzeigen File Inclusion Vulnerability
- 4Images <= 1.7.1 Directory Traversal Vulnerability
- Apache Struts2 'URL' & 'Anchor' tags Arbitrary Java Method Execution Vulnerabilities
- Adobe ColdFusion Authentication Bypass Vulnerability
- Awstats Configuration File Remote Arbitrary Command Execution Vulnerability