CVE-2007-6091 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System (JBS) 2.0, and possibly JiRo's Upload Manager (aka JiRo's Upload System or JUS), allow remote attackers to execute arbitrary SQL commands via the (1) Username (aka Login or Email) or (2) Password field.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.26% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-11-22 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| jiro | banner system |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | JiRo's Banner System 2.0 - 'login.asp' Multiple SQL Injections | 2007-11-17 |
References
- http://osvdb.org/38740
- http://osvdb.org/38741
- http://secunia.com/advisories/27713
- http://securityreason.com/securityalert/3384
- http://www.securityfocus.com/archive/1/483859/100/0/threaded
- http://www.securityfocus.com/bid/26479
- http://osvdb.org/38740
- http://osvdb.org/38741
- http://secunia.com/advisories/27713
- http://securityreason.com/securityalert/3384
- http://www.securityfocus.com/archive/1/483859/100/0/threaded
- http://www.securityfocus.com/bid/26479
→ the Explorer · watch your stack · NVD