Lucene search

K
cveMitreCVE-2008-6225
HistoryFeb 20, 2009 - 11:30 p.m.

CVE-2008-6225

2009-02-2023:30:00
CWE-89
mitre
web.nvd.nist.gov
33
cve-2008-6225
sql injection
info.php
mole group
airline ticket sale script
remote attackers
security vulnerability
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.7

Confidence

Low

EPSS

0.007

Percentile

79.6%

SQL injection vulnerability in info.php in Mole Group Airline Ticket Sale Script allows remote attackers to execute arbitrary SQL commands via the flight parameter. NOTE: the vendor has disputed this issue, stating "crazy hackers and so named Security companies [spread] out such false informations. Such scripts or versions [do not] exist.

Affected configurations

Nvd
Node
mole-groupairline_ticket_sale_scriptMatch-
VendorProductVersionCPE
mole-groupairline_ticket_sale_script-cpe:2.3:a:mole-group:airline_ticket_sale_script:-:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.7

Confidence

Low

EPSS

0.007

Percentile

79.6%

Related for CVE-2008-6225