Unrated severityNVD Advisory· Published Dec 7, 2009· Updated Apr 23, 2026
CVE-2009-4221
CVE-2009-4221
Description
SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-3767.
Affected products
4cpe:2.3:a:smartisoft:phpbazar:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:smartisoft:phpbazar:*:*:*:*:*:*:*:*range: <=2.1.1fix
- cpe:2.3:a:smartisoft:phpbazar:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:smartisoft:phpbazar:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:smartisoft:phpbazar:2.1.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.