Vulnerability Details CVE-2009-4256
Multiple SQL injection vulnerabilities in cource.php in AlefMentor 2.0 and 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) cont_id and (2) courc_id parameters in a pregled action. NOTE: some of these details are obtained from third party information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.3%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2009-4256
-
cpe:2.3:a:truesolution:alefmentor:2.0
-
cpe:2.3:a:truesolution:alefmentor:2.2