CVE-2008-0185 Information
Feb 14, 2021
cve
Description
SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the pid parameter in a profile page (possibly profile.php).
Reference
http://secunia.com/advisories/28328 http://sourceforge.net/project/shownotes.php?release_id=551208&group_id=129681 http://www.securityfocus.com/archive/1/485834/100/0/threaded http://www.securityfocus.com/bid/27161 https://www.exploit-db.com/exploits/4852
Share on: