CVE-2009-4791
N/A
N/A
Summary
Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to addressbook.php, (2) id parameter to recipes.php, (3) year parameter to register.php, (4) poll_id parameter to home.php, and (5) email parameter to lostpw.php.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.familycms.com/blog/2009/03/fcms-182-released/
- http://www.exploit-db.com/exploits/8319
- http://www.securityfocus.com/archive/1/502272/100/0/threaded
- http://sourceforge.net/project/shownotes.php?release_id=672266
- http://sourceforge.net/tracker/?func=detail&aid=2722736&group_id=189733&atid=930513
- http://www.securityfocus.com/bid/34297
- http://secunia.com/advisories/34503
References
- http://www.familycms.com/blog/2009/03/fcms-182-released/
- http://www.exploit-db.com/exploits/8319
- http://www.securityfocus.com/archive/1/502272/100/0/threaded
- http://sourceforge.net/project/shownotes.php?release_id=672266
- http://sourceforge.net/tracker/?func=detail&aid=2722736&group_id=189733&atid=930513
- http://www.securityfocus.com/bid/34297
- http://secunia.com/advisories/34503
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.