CVE-2009-3543
02.10.2009, 19:30
SQL injection vulnerability in _phenotype/admin/login.php in Phenotype CMS before 2.9 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the login name).
Vendor | Product | Version |
---|---|---|
phenotype-cms | phenotype_cms | 𝑥 ≤ 2.8 |
phenotype-cms | phenotype_cms | 1.0 |
phenotype-cms | phenotype_cms | 2.0 |
phenotype-cms | phenotype_cms | 2.1 |
phenotype-cms | phenotype_cms | 2.2 |
phenotype-cms | phenotype_cms | 2.3 |
phenotype-cms | phenotype_cms | 2.4 |
phenotype-cms | phenotype_cms | 2.5 |
phenotype-cms | phenotype_cms | 2.5.1 |
phenotype-cms | phenotype_cms | 2.6 |
phenotype-cms | phenotype_cms | 2.7 |
𝑥
= Vulnerable software versions
References