CVE-2009-2167

Metadata

CVE-2009-2167
6.8
vupen.com, exchange.xforce.ibmcloud.com, exploit-db.com
2009-06-22
2017-09-29 06:09

Description

Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.

Related Vulnerabilities