peter bassill · operator
$ cve CVE-2009-2113 JSON

CVE-2009-2113 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to player.php and the (2) hash parameter to song.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.56% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2009-06-18
Last modified2026-06-16

Affected (1)

VendorProduct
fretsweb projectfretsweb

Public exploits

SourceTitleDate
exploit-dbFretsWeb 1.2 - 'name' Blind SQL Injection2009-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD