CVE-2009-1814
Jevontech Phpenpals < 1.1 - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074.
Exploits (1)
Scores
EPSS
0.0034
EPSS Percentile
56.6%
Details
CWE
CWE-89
Status
published
Products (1)
jevontech/phpenpals
< 1.1
Published
May 29, 2009
Tracked Since
Feb 18, 2026