SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.exploit-db.com/exploits/9027 - |
Information
Published : 2009-07-09 16:30
Updated : 2024-11-21 01:04
NVD link : CVE-2009-2394
Mitre link : CVE-2009-2394
CVE.ORG link : CVE-2009-2394
JSON object : View
Products Affected
smspages
- smspages
mr_saphp_arabic_mobile
- messages_library
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')