Key Information Vulnerability Overview Vulnerability Type: Remote SQL Injection Vulnerability Name: iScripts Easybiller 1.1 Remote SQL Injection CVE ID: CVE-2010-5034 CWE ID: CWE-89 CVSS Base Score: 7.5/10 Risk Level: Medium Vulnerability Details Affected Version: iScripts Easybiller v1.1 Disclosure Date: 2010-06-05 Exploitation Scenario: - Remote: Can be exploited remotely - Authentication Required: No authentication required Impact Scope: - Confidentiality: Partial - Integrity: Partial - Availability: Partial Example URL: Exploitation Command: References http://xforce.iss.net/xforce/xfdb/59150 http://www.vupen.com/english/advisories/2010/1359 http://www.exploit-db.com/exploits/13741/ http://secunia.com/advisories/40088 http://packetstormsecurity.org/1006-exploits/iscripseasybiller-sql.txt