CVE-2008-5131
Multiple SQL injection vulnerabilities in Develop It Easy News And Article System 1.4 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter to article_details.php, and the (2) username and (3) password to the admin panel…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in Develop It Easy News And Article System 1.4 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter to article_details.php, and the (2) username and (3) password to the admin panel (admin/index.php).
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- develop it easy/news and article system
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/32595Vendor Advisory
- http://securityreason.com/securityalert/4607
- http://www.securityfocus.com/bid/32144
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46397
- https://www.exploit-db.com/exploits/7014
- http://secunia.com/advisories/32595Vendor Advisory
- http://securityreason.com/securityalert/4607
- http://www.securityfocus.com/bid/32144
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46397
- https://www.exploit-db.com/exploits/7014
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.