CVE-2008-2903
Awbs Advanced Webhost Billing System - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the viewnews parameter.
Exploits (1)
Scores
EPSS
0.0049
EPSS Percentile
64.9%
Classification
CWE
CWE-89
Status
draft
Affected Products (5)
awbs/advanced_webhost_billing_system
awbs/advanced_webhost_billing_system
awbs/advanced_webhost_billing_system
awbs/advanced_webhost_billing_system
awbs/advanced_webhost_billing_system
Timeline
Published
Jun 30, 2008
Tracked Since
Feb 18, 2026