CVE-2009-2921

Multiple SQL injection vulnerabilities in login.php in MOC Designs PHP News 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) newsuser parameter (User field) and (2) newspassword parameter (Password field).
Configurations

Configuration 1 (hide)

cpe:2.3:a:mocdesigns:php_news:1.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:06

Type Values Removed Values Added
References () http://www.exploit-db.com/exploits/9353 - () http://www.exploit-db.com/exploits/9353 -
References () http://www.vupen.com/english/advisories/2009/2161 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/2161 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/52231 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/52231 -

Information

Published : 2009-08-21 11:30

Updated : 2025-04-09 00:30


NVD link : CVE-2009-2921

Mitre link : CVE-2009-2921

CVE.ORG link : CVE-2009-2921


JSON object : View

Products Affected

mocdesigns

  • php_news
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')