CVE-2008-3591
Twentyone Degrees Symphony <1.7.01 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to index.php.
Exploits (1)
References (5)
Scores
EPSS
0.0044
EPSS Percentile
63.4%
Details
CWE
CWE-89
Status
published
Products (7)
21degrees/symphony
1.1
21degrees/symphony
1.5
21degrees/symphony
1.5.05
21degrees/symphony
1.5.06
21degrees/symphony
1.6.02
21degrees/symphony
1.7
21degrees/symphony
< 1.7.01
Published
Aug 11, 2008
Tracked Since
Feb 18, 2026