CVE-2009-0279
Pardal CMS <0.2.0 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by darkjoker · phpwebappsphp
https://www.exploit-db.com/exploits/7851
Scores
EPSS
0.0023
EPSS Percentile
45.4%
Details
CWE
CWE-89
Status
published
Products (7)
pardalcms/pardalcms
0.1.1
pardalcms/pardalcms
0.1.2
pardalcms/pardalcms
0.1.3
pardalcms/pardalcms
0.1a
pardalcms/pardalcms
0.01b
pardalcms/pardalcms
0.01c
pardalcms/pardalcms
< 0.2.0
Published
Jan 27, 2009
Tracked Since
Feb 18, 2026