CVE-2008-4887
04.11.2008, 00:57
SQL injection vulnerability in index.php in NetRisk 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) profile page (profile.php) or (2) game page (game.php). NOTE: some of these details are obtained from third party information.
Vendor | Product | Version |
---|---|---|
netrisk | netrisk | 𝑥 ≤ 2.0 |
netrisk | netrisk | 1.9.7 |
𝑥
= Vulnerable software versions
References