CVE-2009-0406

Community CMS <0.4 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by darkjoker · phpwebappsphp
https://www.exploit-db.com/exploits/7892

Scores

EPSS 0.0023
EPSS Percentile 45.4%

Details

CWE
CWE-89
Status published
Products (5)
community_cms/community_cms 0.1
community_cms/community_cms 0.1.1
community_cms/community_cms 0.2
community_cms/community_cms 0.3
community_cms/community_cms < 0.4
Published Feb 03, 2009
Tracked Since Feb 18, 2026