CVE-2013-3524
Simpilotgroup Pop UP News - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in popupnewsitem/ in the Pop Up News module 2.0 and possibly earlier for phpVMS allows remote attackers to execute arbitrary SQL commands via the itemid parameter. NOTE: this was originally reported as a problem in phpVMS.
Exploits (1)
References (7)
Scores
EPSS
0.0161
EPSS Percentile
81.5%
Classification
CWE
CWE-89
Status
draft
Affected Products (1)
simpilotgroup/pop_up_news
Timeline
Published
May 10, 2013
Tracked Since
Feb 18, 2026