CVE-2008-5766

Farsi Script Faupload - SQL Injection

Title source: llm

Description

SQL injection vulnerability in download.php in Farsi Script Faupload allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Aria-Security Team · textwebappsphp
https://www.exploit-db.com/exploits/7487

Scores

EPSS 0.0029
EPSS Percentile 51.9%

Classification

CWE
CWE-89
Status draft

Affected Products (1)

fascript/faupload

Timeline

Published Dec 30, 2008
Tracked Since Feb 18, 2026