CVE-2009-2790 identifies a SQL injection vulnerability in SoftBiz Dating Script, specifically affecting the cat_products.php component, which allows remote attackers to execute arbitrary SQL commands via the cid parameter. This vulnerability carries a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity and no authentication, potentially leading to a full compromise of confidentiality, integrity, and availability. Although public exploit code is available on ExploitDB, there is no evidence of active exploitation, it is not listed on CISA's KEV catalog, and it has a very low EPSS score of 0.00127.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:softbizscripts:dating_script:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.