CVE-2008-1398

AuraCMS <2.2.1 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.

Exploits (1)

exploitdb WORKING POC VERIFIED
by NTOS-Team · perlwebappsphp
https://www.exploit-db.com/exploits/5256

Scores

EPSS 0.0046
EPSS Percentile 64.3%

Details

CWE
CWE-89
Status published
Products (3)
auracms/auracms 2.0
auracms/auracms 2.1
auracms/auracms 2.2.1
Published Mar 20, 2008
Tracked Since Feb 18, 2026