CVE-2008-4457
07.10.2008, 00:31
SQL injection vulnerability in inc/inc_statistics.php in MemHT Portal 3.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a stats_res cookie to index.php.
Vendor | Product | Version |
---|---|---|
memht | memht_portal | 𝑥 ≤ 3.9.0 |
memht | memht_portal | 1.0:final |
memht | memht_portal | 1.5:full |
memht | memht_portal | 1.5:update |
memht | memht_portal | 2.0:full |
memht | memht_portal | 2.0:update |
memht | memht_portal | 2.5:full |
memht | memht_portal | 2.5:update |
memht | memht_portal | 2.9:full |
memht | memht_portal | 2.9:update |
memht | memht_portal | 3.0:full |
memht | memht_portal | 3.0:update |
memht | memht_portal | 3.1:full |
memht | memht_portal | 3.1:update |
memht | memht_portal | 3.2:update |
memht | memht_portal | 3.3:full |
memht | memht_portal | 3.3:update |
memht | memht_portal | 3.4:full |
memht | memht_portal | 3.4:update |
memht | memht_portal | 3.4.5:full |
memht | memht_portal | 3.4.5:update |
memht | memht_portal | 3.5.0:full |
memht | memht_portal | 3.6.0 |
memht | memht_portal | 3.6.5 |
memht | memht_portal | 3.7.0 |
memht | memht_portal | 3.7.5 |
memht | memht_portal | 3.8.0 |
memht | memht_portal | 3.8.1 |
memht | memht_portal | 3.8.5 |
𝑥
= Vulnerable software versions
References