CVE-2009-4669 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in RoomPHPlanning 1.6 allow remote attackers to execute arbitrary SQL commands via (1) the loginus parameter to Login.php or (2) the Old Password field to changepwd.php and allow (3) remote authenticated administrators to execute arbitrary SQL commands via the id parameter to admin/userform.php.
Reference
http://secunia.com/advisories/35237 http://www.exploit-db.com/exploits/8797
Share on: