Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-2673 (pnews)

BugsAlert Home > CVE-2008-2673 (pnews)
 
 

SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the shownews parameter.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2673

Learn more about CVE-2008-2673 (pnews)
 
Tags: cve-2008-2673 pnews

Related Items

      FrSIRT - Logitech Desktop Messenger BackWeb Remote Buffer Overflow

      Bugtraq: A paper by Amit Klein (Trusteer): "OpenBSD DNS Cache Poisoning and Multiple O/S Predictable IP ID Vulnerability"

      FrSIRT - rPath Security Update Fixes Tk "ReadImage()" Buffer Overflow Issue

      CVE-2007-6552 (AuraCMS)

      CVE-2008-3836 (firefox)

      TROJ_AGENT.AGSA

      FrSIRT - IBM WebSphere MQ for NonStop Restrictions Bypass Vulnerability

 

Pixel