CVE-2009-2921
Published Aug 21, 2009
Last updated 7 years ago
Overview
- Description
- Multiple SQL injection vulnerabilities in login.php in MOC Designs PHP News 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) newsuser parameter (User field) and (2) newspassword parameter (Password field).
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mocdesigns:php_news:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34D98A56-06A1-4325-8B66-068B5946B089" } ], "operator": "OR" } ] } ]