CVE-2008-2916
30.06.2008, 18:24
Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to showcategory.php and the (2) id parameter to software-description.php.
| Vendor | Product | Version |
|---|---|---|
| preprojects | pre_ads_portal | 𝑥 ≤ 2.0 |
𝑥
= Vulnerable software versions
References