SQL injection vulnerability in content.php in Scripts For Sites (SFS) EZ Career allows remote attackers to execute arbitrary SQL commands via the topic parameter.
References
Configurations
History
21 Nov 2024, 00:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/49486 - | |
References | () http://secunia.com/advisories/32527 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/32037 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/46275 - | |
References | () https://www.exploit-db.com/exploits/6919 - |
Information
Published : 2009-07-14 14:30
Updated : 2024-11-21 00:57
NVD link : CVE-2008-6867
Mitre link : CVE-2008-6867
CVE.ORG link : CVE-2008-6867
JSON object : View
Products Affected
scripts_for_sites
- ez_career
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')