CVE-2009-0646

N/A Unknown
Published: February 18, 2009 Modified: April 23, 2026
View on NVD

Description

Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) password parameters to pcgi/4site.pl, (3) page parameter to print/print.shtml, (4) s and (5) i parameters to portfolio/index.shtml, (6) h parameter to hotel/index.php, (7) id parameter to news/news1.shtml, and the (8) th parameter to faq/index.shtml.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/33733
Source: cve@mitre.org
Vendor Advisory
http://www.osvdb.org/51806
Source: cve@mitre.org
http://www.osvdb.org/51807
Source: cve@mitre.org
http://www.osvdb.org/51808
Source: cve@mitre.org
http://www.osvdb.org/51809
Source: cve@mitre.org
http://www.securityfocus.com/bid/33594
Source: cve@mitre.org
Exploit
http://secunia.com/advisories/33733
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://wsec.ru/wsec-09-002-4site-cms-26-multiple-sql-injections/
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.htbridge.ch/advisory/sql_injection_in_4site_cms.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/51806
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/51807
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/51808
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/51809
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/514376/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/33594
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/48483
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/48486
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/48487
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/48488
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/7964
Source: af854a3a-2127-422b-91ae-364da2661108

28 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.1%
84th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

4site