CVE-2008-4900

Yourfreeworld Classifieds Blaster Script - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Hussin X · textwebappsphp
https://www.exploit-db.com/exploits/6944
exploitdb WORKING POC VERIFIED
by Hussin X · textwebappsphp
https://www.exploit-db.com/exploits/6936

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6944
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/49600
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32062
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2981

Scores

EPSS 0.0052
EPSS Percentile 67.0%

Details

CWE
CWE-89
Status published
Products (1)
yourfreeworld/classifieds_blaster_script
Published Nov 04, 2008
Tracked Since Feb 18, 2026