Unrated severityNVD Advisory· Published Aug 20, 2009· Updated Apr 23, 2026
CVE-2009-2894
CVE-2009-2894
Description
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to product_desc.php, and the cid parameter to (2) showcategory.php and (3) gallery.php.
Affected products
1- cpe:2.3:a:clone2009:ebay_clone:2009:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- osvdb.org/56265nvdExploit
- osvdb.org/56266nvdExploit
- osvdb.org/56268nvdExploit
- packetstormsecurity.org/0907-exploits/clone2009-sql.txtnvdExploit
- secunia.com/advisories/35952nvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/51956nvd
News mentions
0No linked articles in our index yet.