CVE-2008-5131

Publication date

2008-11-18 11:00:00

Family

mitre

State

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Develop It Easy News And Article System 1.4 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter to article_details.php, and the (2) username and (3) password to the admin panel (admin/index.php).