CVE-2009-2394

SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:smspages:smspages:1.0:*:*:*:*:*:*:*
cpe:2.3:a:mr_saphp_arabic_mobile:messages_library:2.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:04

Type Values Removed Values Added
References () http://www.exploit-db.com/exploits/9027 - () http://www.exploit-db.com/exploits/9027 -

Information

Published : 2009-07-09 16:30

Updated : 2024-11-21 01:04


NVD link : CVE-2009-2394

Mitre link : CVE-2009-2394

CVE.ORG link : CVE-2009-2394


JSON object : View

Products Affected

smspages

  • smspages

mr_saphp_arabic_mobile

  • messages_library
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')