CVE-2008-5075

Multiple SQL injection vulnerabilities in E-Uploader Pro 1.0 (aka Uploader PRO), when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) img.php, (b) file.php, (c) mail.php, (d) thumb.php, (e) zip.php, and (f) zipit.php, and (2) the view parameter to (g) browser.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:scriptsfrenzy:e-uploader_pro:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:53

Type Values Removed Values Added
References () http://securityreason.com/securityalert/4596 - () http://securityreason.com/securityalert/4596 -
References () http://www.securityfocus.com/bid/31445 - Exploit () http://www.securityfocus.com/bid/31445 - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/45487 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/45487 -
References () https://www.exploit-db.com/exploits/6596 - () https://www.exploit-db.com/exploits/6596 -

Information

Published : 2008-11-14 18:08

Updated : 2025-04-09 00:30


NVD link : CVE-2008-5075

Mitre link : CVE-2008-5075

CVE.ORG link : CVE-2008-5075


JSON object : View

Products Affected

scriptsfrenzy

  • e-uploader_pro
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')