VYPR

guestbook component

by Drake Team

CVEs (1)

  • CVE-2008-6475Mar 16, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earlier allows remote attackers to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php.