Описание
SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.
SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2010-0723
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56446
- http://4004securityproject.wordpress.com/2010/02/21/ero-auktion-2010-sql-injection-news-php
- http://4004securityproject.wordpress.com/2010/02/21/ero-auktion-v-2-0-sql-injection-news-php
- http://packetstormsecurity.org/1002-exploits/eroauktion20-sql.txt
- http://packetstormsecurity.org/1002-exploits/eroauktion2010-sql.txt
- http://secunia.com/advisories/38666
- http://www.exploit-db.com/exploits/11521
- http://www.exploit-db.com/exploits/11522
Связанные уязвимости
nvd
почти 16 лет назад
SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.