PoC Index

CVE-2008-2652

HIGH 7.5EPSS 1.0%

Multiple SQL injection vulnerabilities in catalog.php in SMEWeb 1.4b and 1.4f allow remote attackers to execute arbitrary SQL commands via the (1) idp and (2) category parameters.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.04% chance of exploitation in the next 30 days, 62th percentile
Published
2008-06-10
Updated
2024-08-07

ExploitDB entries (1)

References

Related