CVE-2008-3366

SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2008-1774.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pligg:pligg_cms:9.9.0:*:*:*:*:*:*:*
cpe:2.3:a:pligg:pligg_cms:9.9.0:beta:*:*:*:*:*:*

History

21 Nov 2024, 00:49

Type Values Removed Values Added
References () http://securityreason.com/securityalert/4063 - () http://securityreason.com/securityalert/4063 -
References () http://www.vupen.com/english/advisories/2008/2214/references - () http://www.vupen.com/english/advisories/2008/2214/references -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/44021 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/44021 -
References () https://www.exploit-db.com/exploits/6146 - () https://www.exploit-db.com/exploits/6146 -

Information

Published : 2008-07-30 17:41

Updated : 2024-11-21 00:49


NVD link : CVE-2008-3366

Mitre link : CVE-2008-3366

CVE.ORG link : CVE-2008-3366


JSON object : View

Products Affected

pligg

  • pligg_cms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')