Unrated severityNVD Advisory· Published Jun 18, 2009· Updated Apr 23, 2026
CVE-2009-2113
CVE-2009-2113
Description
Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to player.php and the (2) hash parameter to song.php.
Affected products
1- cpe:2.3:a:fretsweb_project:fretsweb:1.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- sourceforge.net/forum/forum.phpnvdPatch
- secunia.com/advisories/35492nvdVendor Advisory
- www.exploit-db.com/exploits/8980nvdThird Party AdvisoryVDB Entry
- osvdb.org/55167nvdBroken Link
- osvdb.org/55168nvdBroken Link
News mentions
0No linked articles in our index yet.