CVE-2009-2389

USOLVED NEWSolved 1.1.6 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by jmp-esp · perlwebappsphp
https://www.exploit-db.com/exploits/9042

Scores

EPSS 0.0023
EPSS Percentile 46.1%

Details

CWE
CWE-89
Status published
Products (1)
usolved/newsolved 1.1.6
Published Jul 09, 2009
Tracked Since Feb 18, 2026