Vulnerabilities > Urulu > Urulu

DATE CVE VULNERABILITY TITLE RISK
2008-02-29 CVE-2008-0385 SQL Injection vulnerability in Urulu 2.1
SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO.
network
low complexity
urulu CWE-89
7.5