CVE-2009-2394

SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:smspages:smspages:1.0:*:*:*:*:*:*:*
cpe:2.3:a:mr_saphp_arabic_mobile:messages_library:2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-07-09 16:30

Updated : 2024-02-28 11:21


NVD link : CVE-2009-2394

Mitre link : CVE-2009-2394

CVE.ORG link : CVE-2009-2394


JSON object : View

Products Affected

mr_saphp_arabic_mobile

  • messages_library

smspages

  • smspages
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')