CVE-2009-2389

Metadata

CVE-2009-2389
6.8
exploit-db.com
2009-07-09
2017-09-19 07:07

Description

Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.

Related Vulnerabilities