CVE-2008-0267

Eticket - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters to search.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (4) msg and (5) password parameters to admin.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by L4teral · textwebappsphp
https://www.exploit-db.com/exploits/30996
exploitdb WRITEUP VERIFIED
by L4teral · textwebappsphp
https://www.exploit-db.com/exploits/30997

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39487
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/485835/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39489
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28331
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27173
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3542

Scores

EPSS 0.0182
EPSS Percentile 82.9%

Details

CWE
CWE-89
Status published
Products (1)
eticket/eticket 1.5.5.2
Published Jan 15, 2008
Tracked Since Feb 18, 2026