CVE-2009-2122

Paolo Palmonari Photoracer <1.0 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kacper · textwebappsphp
https://www.exploit-db.com/exploits/8961

Scores

EPSS 0.0069
EPSS Percentile 71.4%

Classification

CWE
CWE-89
Status draft

Affected Products (1)

paolo_palmonari/photoracer_plugin_for_wordpress

Timeline

Published Jun 19, 2009
Tracked Since Feb 18, 2026