CVE-2009-0597
EUVD-2009-060016.02.2009, 17:30
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the benutzername parameter (aka Username field) in a login action.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| w3b_cms | aka_w3blabor_cms | 𝑥 ≤ 3.3.0 |
𝑥
= Vulnerable software versions
References