29495vdb entry
http://www.securityfocus.com/bid/29495 CVE-2008-2629
PLog 1.0.6 - 'albumID' SQL Injection
Record summary
CVE-2008-2629 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitrary SQL commands via the albumId parameter in a ViewAlbum action to index.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPLog 1.0.6 - 'albumID' SQL InjectionExploitDB exploitby DreamTurkNot analyzed1 file
References
4plog-index-sql-injection(42808)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/42808 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-2629 5724exploit
https://www.exploit-db.com/exploits/5724