CVE-2008-3212 Information

Description

Multiple SQL injection vulnerabilities in Scripteen Free Image Hosting Script 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/login.php or the (3) uname or (4) pass parameter to login.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Reference

http://secunia.com/advisories/31083 http://www.securityfocus.com/bid/30216 https://exchange.xforce.ibmcloud.com/vulnerabilities/43772

Share on: