SQL Injection Vulnerability in OneCMS by OneCMS
CVE-2008-7208

Currently unrated

Key Information:

Status
Vendor
CVE Published:
11 September 2009

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2008-7208?

Multiple SQL injection vulnerabilities exist in OneCMS 2.4 and possibly earlier versions, allowing attackers to execute arbitrary SQL commands. The vulnerabilities are triggered through the 'username' parameter in a_login.php and the 'user' parameter in staff.php, posing risks for users of the affected software. If exploited, these SQL injection vulnerabilities could lead to unauthorized data access and compromise the integrity of the application.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.