Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-2598

Multiple SQL injection vulnerabilities in Online Grades & Attendance 3.2.6 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the key parameter in a resetpass action to index.php and (2) remote authenticated users to execute arbitrary SQL commands via the ADD parameter in a mailto action to parents/parents.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.4%
CVSS Severity
CVSS v2 Score 6.5
Products affected by CVE-2009-2598


Contact Us

Shodan ® - All rights reserved