Vulnerability Details CVE-2008-2673
SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the shownews parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.6%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2008-2673
-
cpe:2.3:a:powie:pnews:2.08
-
cpe:2.3:a:powie:pnews:2.10