cve/2008/CVE-2008-1398.md
2024-05-26 14:27:05 +02:00

682 B

CVE-2008-1398

Description

SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.

POC

Reference

Github

No PoCs found on GitHub currently.