CVE-2008-1509

XLPortal <2.2.4 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in index.php in XLPortal 2.2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the query parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by cOndemned · perlwebappsphp
https://www.exploit-db.com/exploits/5293

Scores

EPSS 0.0054
EPSS Percentile 67.7%

Details

CWE
CWE-89
Status published
Products (1)
xlportal/xlportal < 2.2.4
Published Mar 25, 2008
Tracked Since Feb 18, 2026