CVE-2008-6475

Drake Team Drake Cms < 0.2.2.846 - SQL Injection

Title source: rule

Description

SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earlier allows remote attackers to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by EgiX · phpwebappsphp
https://www.exploit-db.com/exploits/5391

Scores

EPSS 0.0032
EPSS Percentile 55.3%

Details

CWE
CWE-89
Status published
Products (2)
drake_team/drake_cms 0.2
drake_team/drake_cms < 0.2.2.846
Published Mar 16, 2009
Tracked Since Feb 18, 2026