Unrated severityNVD Advisory· Published Feb 25, 2009· Updated Apr 23, 2026
CVE-2008-6282
CVE-2008-6282
Description
SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the city parameter in a users_edit_pub action to index.php.
Affected products
4cpe:2.3:a:ortus.nirn:cms_ortus:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:ortus.nirn:cms_ortus:*:*:*:*:*:*:*:*range: <=1.13
- cpe:2.3:a:ortus.nirn:cms_ortus:1.10.1:*:*:*:*:*:*:*
- cpe:2.3:a:ortus.nirn:cms_ortus:1.11:*:*:*:*:*:*:*
- cpe:2.3:a:ortus.nirn:cms_ortus:1.12:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- ortus.nirn.ru/index.phpnvdPatchVendor Advisory
- secunia.com/advisories/32899nvdVendor Advisory
- www.vupen.com/english/advisories/2008/3272nvdVendor Advisory
- osvdb.org/50312nvd
- www.securityfocus.com/bid/32486nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/46886nvd
- www.exploit-db.com/exploits/7237nvd
News mentions
0No linked articles in our index yet.