CVE-2008-2340

Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) lang parameter to (a) advsearch.php, (b) archive.php, and (c) index.php, and the (2) pid parameter to (d) list_tagitems.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:news_manager:news_manager:2.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:46

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/29251 - () http://www.securityfocus.com/bid/29251 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/42461 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/42461 -
References () https://www.exploit-db.com/exploits/5624 - () https://www.exploit-db.com/exploits/5624 -

Information

Published : 2008-05-19 13:20

Updated : 2024-11-21 00:46


NVD link : CVE-2008-2340

Mitre link : CVE-2008-2340

CVE.ORG link : CVE-2008-2340


JSON object : View

Products Affected

news_manager

  • news_manager
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')