CVE-2008-0290

Digitalhive < 2.0_rc2 - SQL Injection

Title source: rule

Description

Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in the gestion_membre.php page to base.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by j0j0 · htmlwebappsphp
https://www.exploit-db.com/exploits/4887

Scores

EPSS 0.0046
EPSS Percentile 64.3%

Details

CWE
CWE-89
Status published
Products (1)
digitalhive/digitalhive < 2.0_rc2
Published Jan 16, 2008
Tracked Since Feb 18, 2026