Описание
Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search_select parameters. NOTE: this issue could not be reproduced by third parties.
Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search_select parameters. NOTE: this issue could not be reproduced by third parties.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2012-6520
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73980
- http://archives.neohapsis.com/archives/bugtraq/2012-03/0046.html
- http://www.darksecurity.de/advisories/2012/SSCHADV2012-005.txt
- http://www.openwall.com/lists/oss-security/2012/04/12/12
- http://www.openwall.com/lists/oss-security/2012/04/13/4
- http://www.openwall.com/lists/oss-security/2012/04/15/1
- http://www.securityfocus.com/bid/52425
Связанные уязвимости
Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search_select parameters. NOTE: this issue could not be reproduced by third parties.