CVE-2009-2428

Tausch Ticket Script 3 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Tausch Ticket Script 3 allow remote attackers to execute arbitrary SQL commands via the (1) userid parameter to suchauftraege_user.php and the (2) descr parameter to vote.php; and other unspecified vectors.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34810
exploitdb WRITEUP VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34809

References (3)

Core 3
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1823
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35725

Scores

EPSS 0.0015
EPSS Percentile 35.8%

Details

CWE
CWE-89
Status published
Products (1)
tauschregal.de/tausch_ticket_script 3
Published Jul 10, 2009
Tracked Since Feb 18, 2026