SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.
References
Configurations
History
21 Nov 2024, 00:44
Type | Values Removed | Values Added |
---|---|---|
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/41153 - | |
References | () https://www.exploit-db.com/exploits/5239 - |
Information
Published : 2008-03-25 23:44
Updated : 2024-11-21 00:44
NVD link : CVE-2008-1513
Mitre link : CVE-2008-1513
CVE.ORG link : CVE-2008-1513
JSON object : View
Products Affected
danneo
- cms
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')