CVE-2008-3251

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
21/07/2008
Last modified:
09/04/2025

Description

Multiple SQL injection vulnerabilities in tplSoccerSite 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the opp parameter to tampereunited/opponent.php; or the id parameter to (2) index.php, (3) player.php, (4) matchdetails.php, or (5) additionalpage.php in tampereunited/.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tpl_design:tplsoccersite:1.0:*:*:*:*:*:*:*