HIGH · 7.5

CVE-2008-6225

SQL injection vulnerability in info.php in Mole Group Airline Ticket Sale Script allows remote attackers to execute arbitrary SQL commands via the flight parameter. NOTE: the vendor has disputed this...

Vulnerability Description

SQL injection vulnerability in info.php in Mole Group Airline Ticket Sale Script allows remote attackers to execute arbitrary SQL commands via the flight parameter. NOTE: the vendor has disputed this issue, stating "crazy hackers and so named Security companies [spread] out such false informations. Such scripts or versions [do not] exist.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Mole-GroupAirline Ticket Sale Script-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-6225?

CVE-2008-6225 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in info.php in Mole Group Airline Ticket Sale Script allows remote attackers to execute arbitrary SQL commands via the flight parameter. NOTE: the vendor has disputed this...

How severe is CVE-2008-6225?

CVE-2008-6225 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-6225?

Check the references section above for vendor advisories and patch information. Affected products include: Mole-Group Airline Ticket Sale Script.