CVE-2009-1742 Information
Feb 14, 2021
cve
Description
code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action as demonstrated via the \UNIunionON\ string which is collapsed into \UNION\ by the filter_sql function.
Reference
http://osvdb.org/54572 http://secunia.com/advisories/35122 http://www.securityfocus.com/bid/35004 http://www.vupen.com/english/advisories/2009/1364 https://exchange.xforce.ibmcloud.com/vulnerabilities/50586 https://www.exploit-db.com/exploits/8709
Share on: