← back
CVE-2008-3580

CVE-2008-3580

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 1.2%
exploitation probability
1.2%top 35% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to visit.php, or the PATH_INFO to the default URI under (2) report/, (3) addreview/, or (4) refer/.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.