CVE-2009-1404
Pastelcms - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user (Username) parameter.
Exploits (1)
Scores
EPSS
0.0034
EPSS Percentile
56.2%
Classification
CWE
CWE-89
Status
draft
Affected Products (1)
pastel/pastelcms
Timeline
Published
Apr 24, 2009
Tracked Since
Feb 18, 2026