CVE-2008-2890 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fflteam_id parameter to teams.php the (2) league_id parameter to leagues.php and the (3) player_id parameter to players.php.
Reference
http://secunia.com/advisories/30795 http://securityreason.com/securityalert/3960 http://www.securityfocus.com/bid/29861 https://exchange.xforce.ibmcloud.com/vulnerabilities/43259 https://www.exploit-db.com/exploits/5889
Share on: