CVE-2009-1245

CCCP Community Clan Portal Pastebin < 2.80 - SQL Injection via Subject, Language, or Nickname Parameters

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in the insert_to_pastebin function in php/cccp-admin/inc/functions.php in CCCP Community Clan Portal Pastebin before 2.80 allow remote attackers to execute arbitrary SQL commands via the (1) subject, (2) language, and (3) nickname parameters to php/cccp-pages/submit.php. NOTE: some of these details are obtained from third party information.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34264
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49426
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34474

Scores

EPSS 0.0119
EPSS Percentile 64.6%

Details

CWE
CWE-89
Status published
Products (7)
cccp-common-clan-portal-pasterbin/cccp_pastebin 2.10
cccp-common-clan-portal-pasterbin/cccp_pastebin 2.20
cccp-common-clan-portal-pasterbin/cccp_pastebin 2.30
cccp-common-clan-portal-pasterbin/cccp_pastebin 2.40
cccp-common-clan-portal-pasterbin/cccp_pastebin 2.50
cccp-common-clan-portal-pasterbin/cccp_pastebin 2.60
cccp-common-clan-portal-pasterbin/cccp_pastebin < 2.70
Published Apr 06, 2009
Tracked Since Feb 18, 2026