CVE-2009-2389 Information

Description

Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6 when magic_quotes_gpc is disabled allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action or (3) the newsid parameter.

Reference

http://secunia.com/advisories/35611 http://www.exploit-db.com/exploits/9042

Share on: