CVE-2008-4521

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
09/10/2008
Last modified:
09/04/2025

Description

SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the INFO_RAID_ID parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php-fusion:world_of_warcraft_tracker_infusion_module:2.0:*:*:*:*:*:*:*