CVE-2009-0597
16.02.2009, 17:30
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the benutzername parameter (aka Username field) in a login action.
Vendor | Product | Version |
---|---|---|
w3b_cms | aka_w3blabor_cms | 𝑥 ≤ 3.3.0 |
𝑥
= Vulnerable software versions
References