CVE-2008-3491

Scripts24 iPost <1.0.1, iTGP <1.0.4 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a report action.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Mr.SQL · textwebappsphp
https://www.exploit-db.com/exploits/6185
exploitdb WORKING POC VERIFIED
by Mr.SQL · textwebappsphp
https://www.exploit-db.com/exploits/6186

Scores

EPSS 0.0329
EPSS Percentile 87.0%

Classification

CWE
CWE-89
Status draft

Affected Products (2)

scripts24/ipost
scripts24/itgp

Timeline

Published Aug 06, 2008
Tracked Since Feb 18, 2026