Vulnerability Description
Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System (JBS) 2.0, and possibly JiRo's Upload Manager (aka JiRo's Upload System or JUS), allow remote attackers to execute arbitrary SQL commands via the (1) Username (aka Login or Email) or (2) Password field.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jiro | Banner System | 2.0 |
Related Weaknesses (CWE)
References
- http://osvdb.org/38740
- http://osvdb.org/38741
- http://secunia.com/advisories/27713
- http://securityreason.com/securityalert/3384
- http://www.securityfocus.com/archive/1/483859/100/0/threaded
- http://www.securityfocus.com/bid/26479Exploit
- http://osvdb.org/38740
- http://osvdb.org/38741
- http://secunia.com/advisories/27713
- http://securityreason.com/securityalert/3384
- http://www.securityfocus.com/archive/1/483859/100/0/threaded
- http://www.securityfocus.com/bid/26479Exploit
FAQ
What is CVE-2007-6091?
CVE-2007-6091 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System (JBS) 2.0, and possibly JiRo's Upload Manager (aka JiRo's Upload System or JUS), allow remote attackers to execute arb...
How severe is CVE-2007-6091?
CVE-2007-6091 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-6091?
Check the references section above for vendor advisories and patch information. Affected products include: Jiro Banner System.