CVE detail
CVE-2008-5070 — CVE-2008-5070
Published 2008-11-14 · Modified 2026-06-16 · Vendor pro_chat_rooms · Product pro_chat_rooms · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0097
EPSS probability
exploitation probability, 30d
59.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the gud parameter to (1) profiles/index.php and (2) profiles/admin.php.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References