CVE-2008-5088 Information

Description

Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) email.php and (2) question.php a different vector than CVE-2008-1909.

Reference

http://securityreason.com/securityalert/4599 http://www.securityfocus.com/bid/31279 https://www.exploit-db.com/exploits/6510

Share on: