CVE-2009-4221
07.12.2009, 17:30
SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-3767.
| Vendor | Product | Version |
|---|---|---|
| smartisoft | phpbazar | 𝑥 ≤ 2.1.1fix |
| smartisoft | phpbazar | 2.0.2 |
| smartisoft | phpbazar | 2.1.0 |
| smartisoft | phpbazar | 2.1.1 |
𝑥
= Vulnerable software versions
References