CVE-2009-3261

LiveStreet 0.2 - Unauthenticated SQL Injection via Update Script

Title source: llm
STIX 2.1

Description

update/update_0.1.2_to_0.2.php in LiveStreet 0.2 does not require administrative authentication, which allows remote attackers to perform DROP TABLE operations via unspecified vectors.

References (1)

Core 1
Core References

Scores

EPSS 0.0144
EPSS Percentile 69.9%

Details

CWE
CWE-287
Status published
Products (1)
livestreet/livestreet 0.2
Published Sep 18, 2009
Tracked Since Feb 18, 2026