Back

CVE-2002-2304

SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter.

Published: Dec 31, 2002 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (2)

Vendor Product Version
myphpsoft myphplinks 2.1.9
myphpsoft myphplinks 2.2.0

GitHub Security Advisory GHSA-w5rv-gg7m-gm52

SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 0.96%

Top 42% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub