Vulnerability Details CVE-2008-5859
SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the show_page parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.0%
CVSS Severity
CVSS v2 Score 5.1
Products affected by CVE-2008-5859
-
cpe:2.3:a:constructr:constructr-cms:*
-
cpe:2.3:a:constructr:constructr-cms:3.00.0
-
cpe:2.3:a:constructr:constructr-cms:3.00.1
-
cpe:2.3:a:constructr:constructr-cms:3.00.2
-
cpe:2.3:a:constructr:constructr-cms:3.01.0
-
cpe:2.3:a:constructr:constructr-cms:3.01.1
-
cpe:2.3:a:constructr:constructr-cms:3.01.2
-
cpe:2.3:a:constructr:constructr-cms:3.01.3
-
cpe:2.3:a:constructr:constructr-cms:3.01.4
-
cpe:2.3:a:constructr:constructr-cms:3.01.5
-
cpe:2.3:a:constructr:constructr-cms:3.01.6
-
cpe:2.3:a:constructr:constructr-cms:3.01.7
-
cpe:2.3:a:constructr:constructr-cms:3.01.8
-
cpe:2.3:a:constructr:constructr-cms:3.01.9
-
cpe:2.3:a:constructr:constructr-cms:3.02.0
-
cpe:2.3:a:constructr:constructr-cms:3.02.1
-
cpe:2.3:a:constructr:constructr-cms:3.02.2
-
cpe:2.3:a:constructr:constructr-cms:3.02.3
-
cpe:2.3:a:constructr:constructr-cms:3.02.4