CVE-2008-5806

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
31/12/2008
Last modified:
09/04/2025

Description

SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka admin field). NOTE: some of these details are obtained from third party information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:deltascripts:php_classifieds:*:*:*:*:*:*:*:* 7.5 (including)
cpe:2.3:a:deltascripts:php_classifieds:6.0.5:*:*:*:*:*:*:*
cpe:2.3:a:deltascripts:php_classifieds:6.04:*:*:*:*:*:*:*
cpe:2.3:a:deltascripts:php_classifieds:6.18:*:*:*:*:*:*:*
cpe:2.3:a:deltascripts:php_classifieds:6.19:*:*:*:*:*:*:*
cpe:2.3:a:deltascripts:php_classifieds:6.20:*:*:*:*:*:*:*
cpe:2.3:a:deltascripts:php_classifieds:7.0:*:*:*:*:*:*:*
cpe:2.3:a:deltascripts:php_classifieds:7.1:*:*:*:*:*:*:*
cpe:2.3:a:deltascripts:php_classifieds:7.2:*:*:*:*:*:*:*
cpe:2.3:a:deltascripts:php_classifieds:7.3:*:*:*:*:*:*:*