CVE-2008-2754
Efiction - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in toplists.php in eFiction 3.0 and 3.4.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the list parameter.
Exploits (1)
Scores
EPSS
0.0049
EPSS Percentile
64.9%
Classification
CWE
CWE-89
Status
draft
Affected Products (2)
efiction/efiction
efiction/efiction
Timeline
Published
Jun 18, 2008
Tracked Since
Feb 18, 2026