Beveiligingsadvies

CVE-2008-2902

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2008-06-30 18:00:00
Laatst bijgewerkt 2024-08-07 09:21:34
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: The que_id parameter to forum_answer.php is already covered by CVE-2007-4085.