Vulnerability Description
SQL injection vulnerability in product.detail.php in Kalptaru Infotech Comparison Engine Power Script 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kalptaru Infotech | Comparison Engine Power Script | 1.0 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/30729ExploitVendor Advisory
- http://www.securityfocus.com/bid/29768Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43138
- https://www.exploit-db.com/exploits/5834
- http://secunia.com/advisories/30729ExploitVendor Advisory
- http://www.securityfocus.com/bid/29768Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43138
- https://www.exploit-db.com/exploits/5834
FAQ
What is CVE-2008-2791?
CVE-2008-2791 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in product.detail.php in Kalptaru Infotech Comparison Engine Power Script 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
How severe is CVE-2008-2791?
CVE-2008-2791 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-2791?
Check the references section above for vendor advisories and patch information. Affected products include: Kalptaru Infotech Comparison Engine Power Script.