CVE-2008-1496

critical

Description

Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to (a) membre.php, and the (2) timestamp parameter to (b) the details action in achat/historique_commandes.php and (c) the facture action in factures/facture_html.php.

References

https://www.exploit-db.com/exploits/5281

https://exchange.xforce.ibmcloud.com/vulnerabilities/41353

https://exchange.xforce.ibmcloud.com/vulnerabilities/41341

http://secunia.com/advisories/29466

Details

Source: Mitre, NVD

Published: 2008-03-25

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00509