CVE-2009-2921

Multiple SQL injection vulnerabilities in login.php in MOC Designs PHP News 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) newsuser parameter (User field) and (2) newspassword parameter (Password field).
Configurations

Configuration 1 (hide)

cpe:2.3:a:mocdesigns:php_news:1.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-08-21 11:30

Updated : 2025-04-09 00:30


NVD link : CVE-2009-2921

Mitre link : CVE-2009-2921

CVE.ORG link : CVE-2009-2921


JSON object : View

Products Affected

mocdesigns

  • php_news
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')