Security Advisory

CVE-2008-5131

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2008-11-18 11:00:00
Last updated 2024-08-07 10:40:17
Assigner mitre
State PUBLISHED

Description

Multiple SQL injection vulnerabilities in Develop It Easy News And Article System 1.4 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter to article_details.php, and the (2) username and (3) password to the admin panel (admin/index.php).