VulnerabilityModified
CVE-2008-6622
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
HIGH 7.5EPSS 0.97%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- webbdomian/post card
- Source
- cve@mitre.org
References
- http://osvdb.org/49823Exploit
- http://secunia.com/advisories/32494Vendor Advisory
- http://www.securityfocus.com/bid/32097Exploit
- https://www.exploit-db.com/exploits/6977
- http://osvdb.org/49823Exploit
- http://secunia.com/advisories/32494Vendor Advisory
- http://www.securityfocus.com/bid/32097Exploit
- https://www.exploit-db.com/exploits/6977
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.