Security Advisory

CVE-2009-3505

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-09-30 15:00:00
Last updated 2024-08-07 06:31:10
Assigner mitre
State PUBLISHED

Description

SQL injection vulnerability in view_news.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter. NOTE: the game_id vector is already covered by CVE-2008-4460.