CVE-2009-3252

Multiple SQL injection vulnerabilities in news.php in Rock Band CMS 0.10 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) id parameters.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:dave_robinson:rockbandcms:0.10:*:*:*:*:*:*:*

Information

Published : 2009-09-18 13:30

Updated : 2017-09-18 18:29


NVD link : CVE-2009-3252

Mitre link : CVE-2009-3252


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

dave_robinson

  • rockbandcms