CVE-2009-2790 Information

Description

SQL injection vulnerability in cat_products.php in SoftBiz Dating Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: this might overlap CVE-2006-3271.4.

Reference

http://packetstormsecurity.org/0907-exploits/softbizdating-sql.txt http://www.securityfocus.com/bid/35896 https://exchange.xforce.ibmcloud.com/vulnerabilities/52158

Share on: