cve/2015/CVE-2015-6009.md

19 lines
774 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2015-6009](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6009)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to rss.php or (2) the sqlQuery parameter to search.php, a different issue than CVE-2015-7382.
### POC
#### Reference
- http://www.kb.cert.org/vuls/id/374092
- https://www.exploit-db.com/exploits/38292/
#### Github
No PoCs found on GitHub currently.