VYPR

Online Fantasy Football League

by Offl

CVEs (1)

  • CVE-2008-2890Jun 27, 2008
    risk 0.03cvss epss 0.00

    Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fflteam_id parameter to teams.php, the (2) league_id parameter to leagues.php, and the (3) player_id parameter to players.php.