CVE-2008-3291

AproxEngine 5.1.0.4 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in index.php in AproxEngine (aka Aprox CMS Engine) 5.1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mr.SQL · textwebappsphp
https://www.exploit-db.com/exploits/6098

Scores

EPSS 0.0044
EPSS Percentile 62.6%

Classification

CWE
CWE-89
Status draft

Affected Products (2)

aprox/aprox_cms_engine
aprox/aproxengine

Timeline

Published Jul 24, 2008
Tracked Since Feb 18, 2026