peter bassill · operator
$ cve CVE-2008-6371 JSON

CVE-2008-6371 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2% (pctl 80)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the username (Username parameter).

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.01% — more likely to be exploited than 80% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2009-03-02
Last modified2026-06-16

Affected (1)

VendorProduct
ocean12techmembership manager pro

Public exploits

SourceTitleDate
exploit-dbOcean12 Membership Manager Pro - Authentication Bypass2008-11-27

References

→ the Explorer  ·  watch your stack  ·  NVD