CVE-2009-2307
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
02/07/2009
Last modified:
09/04/2025
Description
SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter in a viewrecords action to modules.php.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:maxdev:cwguestbook:*:*:*:*:*:*:*:* | 2.1 (including) | |
cpe:2.3:a:maxdev:md-pro:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page