Description
SQL injection vulnerability in mod/poll/comment.php in the vote module in Danneo CMS 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the comtext parameter, in conjunction with crafted comname and comtitle parameters, in a poll action to index.php, related to incorrect input sanitization in base/danneo.function.php.
References (3)
Core 3
Core References
Exploit x_refsource_misc
http://packetstormsecurity.org/0908-exploits/danneo052-sql.txt
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36440
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2459
Scores
EPSS
0.0116
EPSS Percentile
64.0%
Details
CWE
CWE-89
Status
published
Products (3)
danneo/cms
0.5
danneo/cms
0.5.1
danneo/cms
< 0.5.2
Published
Sep 09, 2009
Tracked Since
Feb 18, 2026