CVE-2008-1398
AuraCMS <2.2.1 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by NTOS-Team · perlwebappsphp
https://www.exploit-db.com/exploits/5256
Scores
EPSS
0.0046
EPSS Percentile
64.3%
Details
CWE
CWE-89
Status
published
Products (3)
auracms/auracms
2.0
auracms/auracms
2.1
auracms/auracms
2.2.1
Published
Mar 20, 2008
Tracked Since
Feb 18, 2026