CVE-2008-6311

Butterflymedia Butterfly Organizer - SQL Injection

Title source: rule

Description

SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Osirys · textwebappsphp
https://www.exploit-db.com/exploits/7411
exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/5797

Scores

EPSS 0.0073
EPSS Percentile 72.4%

Classification

CWE
CWE-89
Status draft

Affected Products (1)

butterflymedia/butterfly_organizer

Timeline

Published Feb 27, 2009
Tracked Since Feb 18, 2026