VYPR

CandyPress (CP)

by Shoppingtree

CVEs (1)

  • CVE-2008-0737Feb 13, 2008
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the helpfield parameter.