cpe:/a:lasernet_cms:lasernet_cms:1.5 cpe:/a:lasernet_cms:lasernet_cms:1.11 CVE-2008-1913 2008-04-22T00:41:00.000-04:00 2017-09-28T21:30:56.223-04:00 7.5 NETWORK LOW NONE PARTIAL PARTIAL PARTIAL http://nvd.nist.gov 2008-04-22T13:46:00.000-04:00 ALLOWS_OTHER_ACCESS BID 28804 SECUNIA 29734 EXPLOIT-DB 5454 VUPEN ADV-2008-1239 XF lasernet-index-sql-injection(41838) SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the new parameter in a new action.