CVE-2009-1245
CCCP Community Clan Portal Pastebin < 2.80 - SQL Injection via Subject, Language, or Nickname Parameters
Title source: llmDescription
Multiple SQL injection vulnerabilities in the insert_to_pastebin function in php/cccp-admin/inc/functions.php in CCCP Community Clan Portal Pastebin before 2.80 allow remote attackers to execute arbitrary SQL commands via the (1) subject, (2) language, and (3) nickname parameters to php/cccp-pages/submit.php. NOTE: some of these details are obtained from third party information.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/34264
Product x_refsource_confirm
http://sourceforge.net/project/shownotes.php?release_id=670960
Exploit, Patch x_refsource_confirm
http://jcsfog.cvs.sourceforge.net/viewvc/jcsfog/CCCP-Pastebin/php/cccp-admin/inc/functions.php?r1=1.10&r2=1.11
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49426
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34474
Scores
EPSS
0.0119
EPSS Percentile
64.6%
Details
CWE
CWE-89
Status
published
Products (7)
cccp-common-clan-portal-pasterbin/cccp_pastebin
2.10
cccp-common-clan-portal-pasterbin/cccp_pastebin
2.20
cccp-common-clan-portal-pasterbin/cccp_pastebin
2.30
cccp-common-clan-portal-pasterbin/cccp_pastebin
2.40
cccp-common-clan-portal-pasterbin/cccp_pastebin
2.50
cccp-common-clan-portal-pasterbin/cccp_pastebin
2.60
cccp-common-clan-portal-pasterbin/cccp_pastebin
< 2.70
Published
Apr 06, 2009
Tracked Since
Feb 18, 2026