CVE-2009-1245
06.04.2009, 16:30
Multiple SQL injection vulnerabilities in the insert_to_pastebin function in php/cccp-admin/inc/functions.php in CCCP Community Clan Portal Pastebin before 2.80 allow remote attackers to execute arbitrary SQL commands via the (1) subject, (2) language, and (3) nickname parameters to php/cccp-pages/submit.php. NOTE: some of these details are obtained from third party information.
Vendor | Product | Version |
---|---|---|
cccp-common-clan-portal-pasterbin | cccp_pastebin | 𝑥 ≤ 2.70 |
cccp-common-clan-portal-pasterbin | cccp_pastebin | 2.10 |
cccp-common-clan-portal-pasterbin | cccp_pastebin | 2.20 |
cccp-common-clan-portal-pasterbin | cccp_pastebin | 2.30 |
cccp-common-clan-portal-pasterbin | cccp_pastebin | 2.40 |
cccp-common-clan-portal-pasterbin | cccp_pastebin | 2.50 |
cccp-common-clan-portal-pasterbin | cccp_pastebin | 2.60 |
𝑥
= Vulnerable software versions
References