CVE-2008-6475
16.03.2009, 16:30
SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earlier allows remote attackers to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php.
Vendor | Product | Version |
---|---|---|
drake_team | drake_cms | 𝑥 ≤ 0.2.2.846 |
drake_team | drake_cms | 𝑥 ≤ 0.2.2_alpha_rev.846 |
drake_team | drake_cms | 𝑥 ≤ 0.3.2 |
drake_team | drake_cms | 𝑥 ≤ 0.3.3 |
drake_team | drake_cms | 𝑥 ≤ 0.3.4b |
drake_team | drake_cms | 𝑥 ≤ 0.3.5 |
drake_team | drake_cms | 𝑥 ≤ 0.3.6 |
drake_team | drake_cms | 𝑥 ≤ 0.3.7 |
drake_team | drake_cms | 𝑥 ≤ 0.3.7_beta |
drake_team | drake_cms | 𝑥 ≤ 0.3.8_beta |
drake_team | drake_cms | 𝑥 ≤ 0.3.9 |
drake_team | drake_cms | 𝑥 ≤ 0.4.0 |
drake_team | drake_cms | 𝑥 ≤ 0.4.0b |
drake_team | drake_cms | 𝑥 ≤ 0.4.1 |
drake_team | drake_cms | 𝑥 ≤ 0.4.10_rc6 |
drake_team | drake_cms | 𝑥 ≤ 0.4.11 |
drake_team | drake_cms | 0.2 |
𝑥
= Vulnerable software versions