CVE-2010-2339
Subdreamer CMS 3.x.x - SQL Injection via categoryids[] Parameter
Title source: llmDescription
SQL injection vulnerability in admin/pages.php in Subdreamer CMS 3.x.x allows remote attackers to execute arbitrary SQL commands via the categoryids[] parameter in an update_pages action.
References (6)
Core 6
Core References
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1476
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/40849
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/511818
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.org/1006-advisories/major_rls73.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/59441
Various Sources x_refsource_misc
http://www.majorsecurity.net/subdreamer_cms_sql_injection.php
Scores
EPSS
0.0126
EPSS Percentile
66.5%
Details
CWE
CWE-89
Status
published
Products (7)
subdreamer/subdreamer
3.0.0
subdreamer/subdreamer
3.0.1
subdreamer/subdreamer
3.0.2
subdreamer/subdreamer
3.0.3
subdreamer/subdreamer
3.0.4
subdreamer/subdreamer
3.1.0
subdreamer/subdreamer
3.1.1
Published
Jun 18, 2010
Tracked Since
Feb 18, 2026