CVE-2009-2113 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to player.php and the (2) hash parameter to song.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.56% — more likely to be exploited than 85% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-06-18 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| fretsweb project | fretsweb |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | FretsWeb 1.2 - 'name' Blind SQL Injection | 2009-06-17 |
References
- http://osvdb.org/55167
- http://osvdb.org/55168
- http://secunia.com/advisories/35492
- http://sourceforge.net/forum/forum.php?forum_id=966939
- https://www.exploit-db.com/exploits/8980
- http://osvdb.org/55167
- http://osvdb.org/55168
- http://secunia.com/advisories/35492
- http://sourceforge.net/forum/forum.php?forum_id=966939
- https://www.exploit-db.com/exploits/8980
→ the Explorer · watch your stack · NVD