28594Third-party advisory
http://secunia.com/advisories/28594 CVE-2008-0397
aflog 1.01 - Cross-Site Scripting / SQL Injection
Record summary
CVE-2008-0397 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to comments.php and (2) an unspecified parameter to view.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBaflog 1.01 - Cross-Site Scripting / SQL InjectionExploitDB exploitby shinmaiNot analyzed1 file
References
627398vdb entry
http://www.securityfocus.com/bid/27398 ADV-2008-0255vdb entry
http://www.vupen.com/english/advisories/2008/0255 aflog-comments-sql-injection(39825)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39825 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-0397 4958exploit
https://www.exploit-db.com/exploits/4958