CVE Database
/

CVE-2008-1496

Back to search

CVE-2008-1496

Published: Mar 25, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to (a) membre.php, and the (2) timestamp parameter to (b) the details action in achat/historique_commandes.php and (c) the facture action in factures/facture_html.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

29466
third-party-advisory
x_refsource_SECUNIA
5281
exploit
x_refsource_EXPLOIT-DB
28346
vdb-entry
x_refsource_BID
peel-membre-sql-injection(41353)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now