Vulnerabilities > Urulu > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-02-29 | CVE-2008-0385 | SQL Injection vulnerability in Urulu 2.1 SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO. | 7.5 |