---
cve: "CVE-2015-6009"
severity: "LOW"
cvss: 3.1
epss: "1.5%"
vendor: "n/a"
kev: false
exploited: false
published: "2015-09-28 02:59:05"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T07:44:30+02:00"
---

# CVE-2015-6009

> 3.1 LOW · 🧪 PoC

## Beschreibung

Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to rss.php or (2) the sqlQuery parameter to search.php, a different issue than CVE-2015-7382.

## Exploit-Evidenz

- [EDB-38292 — refbase 0.9.6 - Multiple Vulnerabilities](https://www.exploit-db.com/exploits/38292)

## Referenzen

- <https://www.exploit-db.com/exploits/38292/>
- <http://www.kb.cert.org/vuls/id/374092>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2015-6009) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
