CVE-2008-4651 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id parameter in an editrecord action to admin/cms/nav.php.
Reference
http://www.digitrustgroup.com/advisories/web-application-security-jetbox http://www.securityfocus.com/bid/31824 https://exchange.xforce.ibmcloud.com/vulnerabilities/45986
Share on: