CVE-2008-2902

Publication date

2008-06-30 18:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: The que_id parameter to forum_answer.php is already covered by CVE-2007-4085.