Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-0147 (SmallNuke)

BugsAlert Home > CVE-2008-0147 (SmallNuke)
 
 

SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0147

Learn more about CVE-2008-0147 (SmallNuke)
 
Tags: cve-2008-0147 smallnuke

Related Items

      CVE-2007-5858 (Safari)

      FrSIRT - Downline Goldmine Builder "id" Remote SQL Injection Vulnerability

      CVE-2008-1153 (Cisco IOS)

      Vuln: Microsoft Internet Explorer HTML Objects 'substringData()' Remote Code Execution Vulnerability

      CVE-2008-4358 (spaw_php)

      CVE-2008-1786 (Desktop Management Suite, unicenter_desktop_management_bundle, Unicenter Asset Ma...)

      CVE-2008-5033 (kernel)

 

Pixel