Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Cheebahawk215

#36335of 53,622
7.5Total CVSS
Vulnerabilities · 1
PT-2008-2391
7.5
2008-02-13
Phil Taylor · Phil Taylor Comments · CVE-2008-0773
**Name of the Vulnerable Software and Affected Versions** Phil Taylor Comments (com comments, aka Review Script) versions 0.5.8.5g and earlier **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the `id` parameter. **Recommendations** For versions 0.5.8.5g and earlier, avoid using the `id` parameter in affected API endpoints until the issue is resolved.