CVE-2008-6725 Information

Description

Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php.

Reference

http://osvdb.org/51118 http://secunia.com/advisories/33375 http://www.cmscout.co.za/index.php?page=news&id=30 http://www.securityfocus.com/bid/33068 https://exchange.xforce.ibmcloud.com/vulnerabilities/47659 https://www.exploit-db.com/exploits/7625

Share on: