CVE-2009-2640

Metadata

CVE-2009-2640
7.5
packetstormsecurity.org, exploit-db.com, vupen.com, exchange.xforce.ibmcloud.com, exchange.xforce.ibmcloud.com
2009-07-28
2018-01-11 07:07

Description

Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action.

Related Vulnerabilities