Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-1398 (AuraCMS)

BugsAlert Home > CVE-2008-1398 (AuraCMS)
 
 

SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1398

Learn more about CVE-2008-1398 (AuraCMS)
 
Tags: cve-2008-1398 auracms

Related Items

      D-Link MPEG4 SHM (Audio) Control ActiveX Control "Url" Property Buffer Overflow

      CVE-2008-1027 (Mac OS X Server)

      Brief: Web security firm warns of obfuscated code

      CVE-2007-6252 (STRunner)

      UPDATED: KU implements a new Password Policy

      CVE-2008-3090 (blognplus)

      Sun Solstice AdminSuite sadmind adm_build_path()Buffer Overflow Vulnerability

 

Pixel