CVE-2009-3531

Universe Cms - SQL Injection

Title source: rule

Description

SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mr.tro0oqy · perlwebappsphp
https://www.exploit-db.com/exploits/9099

Scores

EPSS 0.0036
EPSS Percentile 57.8%

Details

CWE
CWE-89
Status published
Products (1)
universe/universe_cms 1.0.6
Published Oct 02, 2009
Tracked Since Feb 18, 2026