CVE-2011-0510 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2% (pctl 81)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the oid parameter in an add_other action.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.04% — more likely to be exploited than 81% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-01-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| awbs | advanced webhost billing system |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | AWBS 2.9.2 - 'cart.php' Blind SQL Injection | 2011-01-16 |
References
→ the Explorer · watch your stack · NVD