CVE-2011-2944
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0583 (5.8%)
Percentile: 90.6%
EPSS: 2026-05-06
Affects
megalab:the_uploaderTechnical description
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.
Published: 8/12/2014, 8:55:03 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://osvdb.org/79508
- http://packetstormsecurity.org/files/110166/The-Uploader-2.0.4-Eng-Ita-Remote-File-Upload.html
- http://secunia.com/advisories/48141
- http://sourceforge.net/p/theuploader/news/2011/07/the-uploader-205-released
- http://www.exploit-db.com/exploits/18518
- http://www.securityfocus.com/bid/52156
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73471
- http://osvdb.org/79508