CVE-2009-2788 Information

Description

Multiple SQL injection vulnerabilities in Mobilelib GOLD 3 allow remote attackers to execute arbitrary SQL commands via the (1) adminName parameter to cp/auth.php (2) cid parameter to artcat.php and (3) catid parameter to show.php.

Reference

http://www.exploit-db.com/exploits/9327 http://www.securityfocus.com/bid/35910

Share on: