CVE-2009-0750

txtSQL 2.2 Final - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in login.php in the smNews example script for txtSQL 2.2 Final allows remote attackers to execute arbitrary SQL commands via the username parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by x0r · textwebappsphp
https://www.exploit-db.com/exploits/8076

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/48813
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8076

Scores

EPSS 0.0053
EPSS Percentile 67.1%

Details

CWE
CWE-89
Status published
Products (1)
tombstone/smnews
Published Mar 02, 2009
Tracked Since Feb 18, 2026