CVE-2008-5582

Nukedit <4.9 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the email parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by r3dm0v3 · perlwebappsphp
https://www.exploit-db.com/exploits/5192

Scores

EPSS 0.0041
EPSS Percentile 61.6%

Details

CWE
CWE-89
Status published
Products (7)
nukedit/nukedit 4.9.0
nukedit/nukedit 4.9.1
nukedit/nukedit 4.9.2
nukedit/nukedit 4.9.3
nukedit/nukedit 4.9.6
nukedit/nukedit 4.9.7b
nukedit/nukedit 4.9.8
Published Dec 15, 2008
Tracked Since Feb 18, 2026