Qihoo 360 · 360 Web Manager · CVE-2008-0430
**Name of the Vulnerable Software and Affected Versions**
360 Web Manager version 3.0
**Description**
A SQL injection issue exists, allowing remote attackers to execute arbitrary SQL commands. This is achieved via the `IDFM` parameter in the form.php file.
**Recommendations**
For 360 Web Manager version 3.0, avoid using the `IDFM` parameter in the form.php file until a patch is available. As a temporary workaround, consider restricting access to the form.php file to minimize the risk of exploitation.