CVE-2010-2339

Subdreamer CMS 3.x.x - SQL Injection via categoryids[] Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in admin/pages.php in Subdreamer CMS 3.x.x allows remote attackers to execute arbitrary SQL commands via the categoryids[] parameter in an update_pages action.

References (6)

Core 6
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1476
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/40849
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/511818
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.org/1006-advisories/major_rls73.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/59441

Scores

EPSS 0.0126
EPSS Percentile 66.5%

Details

CWE
CWE-89
Status published
Products (7)
subdreamer/subdreamer 3.0.0
subdreamer/subdreamer 3.0.1
subdreamer/subdreamer 3.0.2
subdreamer/subdreamer 3.0.3
subdreamer/subdreamer 3.0.4
subdreamer/subdreamer 3.1.0
subdreamer/subdreamer 3.1.1
Published Jun 18, 2010
Tracked Since Feb 18, 2026