Unrated severityNVD Advisory· Published Jul 28, 2009· Updated Apr 23, 2026
CVE-2009-2640
CVE-2009-2640
Description
Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action.
Affected products
1- cpe:2.3:a:interlogy:profile_manager:-:-:basic:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.vupen.com/english/advisories/2009/1529nvdVendor Advisory
- packetstormsecurity.org/files/110437/Interlogy-Profile-Manager-Basic-Insecure-Cookie-Handling.htmlnvd
- www.exploit-db.com/exploits/8895nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/50992nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/73691nvd
News mentions
0No linked articles in our index yet.