CVE-2015-6009 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 1.5% (pctl 74)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to rss.php or (2) the sqlQuery parameter to search.php, a different issue than CVE-2015-7382.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.53% — more likely to be exploited than 74% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2015-09-28 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| refbase | refbase |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | refbase 0.9.6 - Multiple Vulnerabilities | 2015-09-23 |
References
→ the Explorer · watch your stack · NVD