29297Third-party advisory
http://secunia.com/advisories/29297 CVE-2008-1272
BM Classifieds 20080409 - Multiple SQL Injections
Record summary
CVE-2008-1272 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in BM Classifieds 20080309 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showad.php and the (2) ad parameter to pfriendly.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBBM Classifieds 20080409 - Multiple SQL InjectionsExploitDB exploitby xcorpitxNot analyzed1 file
References
528159vdb entry
http://www.securityfocus.com/bid/28159 bmclassifieds-showad-sql-injection(41066)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41066 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-1272 5223exploit
https://www.exploit-db.com/exploits/5223