CVE-2009-3495 Information

Description

SQL injection vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the mag_id parameter a different vector than CVE-2008-4465.

Reference

http://antisecurity.org/dvd-zone-view_mag-phpmag_id-bsqlxss-multiple-remote-vulnerabilities.antisecurity http://secunia.com/advisories/36843 http://www.securityfocus.com/bid/36487 http://www.vupen.com/english/advisories/2009/2735

Share on: