SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.
References
Link | Resource |
---|---|
http://www.exploit-db.com/exploits/9027 |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2009-07-09 16:30
Updated : 2024-02-28 11:21
NVD link : CVE-2009-2394
Mitre link : CVE-2009-2394
CVE.ORG link : CVE-2009-2394
JSON object : View
Products Affected
mr_saphp_arabic_mobile
- messages_library
smspages
- smspages
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')