CVE-2008-3867 Information

Description

SQL injection vulnerability in spaces/emailuser.php in Interact 2.4.1 allows remote attackers to execute arbitrary SQL commands via the email_user_key parameter.

Reference

http://secunia.com/advisories/32359 http://secunia.com/secunia_research/2008-44/ http://securityreason.com/securityalert/4537 http://sourceforge.net/tracker/index.php?func=detail&aid=2208205&group_id=69681&atid=525406 http://www.securityfocus.com/archive/1/497967/100/0/threaded http://www.securityfocus.com/bid/32014 https://exchange.xforce.ibmcloud.com/vulnerabilities/46267

Share on: