Description
Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL commands via unknown parameters to the gbook module and unspecified other components.
References (4)
Core 4
Core References
Various Sources x_refsource_confirm
http://www.clansphere.net/index/news/view/id/405/
Patch, Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1794
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/35576
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35694
Scores
EPSS
0.0106
EPSS Percentile
61.1%
Details
CWE
CWE-89
Status
published
Products (11)
clansphere/clansphere
2007.4
clansphere/clansphere
2007.4.1
clansphere/clansphere
2007.4.2
clansphere/clansphere
2007.4.3
clansphere/clansphere
2007.4.4
clansphere/clansphere
2008
clansphere/clansphere
2008.1
clansphere/clansphere
2008.2
clansphere/clansphere
2008.2.1
clansphere/clansphere
2009.0 rc1 (3 CPE variants)
... and 1 more
Published
Jul 07, 2009
Tracked Since
Feb 18, 2026