Описание
SQL injection vulnerability in index.php in Prado Portal 1.2.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
SQL injection vulnerability in index.php in Prado Portal 1.2.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2010-4958
- http://packetstormsecurity.org/1008-exploits/pradoportal-xss.txt
- http://secunia.com/advisories/40902
- http://securityreason.com/securityalert/8468
- http://www.htbridge.ch/advisory/xss_vulnerability_in_prado_portal.html
- http://www.securityfocus.com/archive/1/512888/100/0/threaded
- http://www.vupen.com/english/advisories/2010/2026
Связанные уязвимости
nvd
больше 14 лет назад
SQL injection vulnerability in index.php in Prado Portal 1.2.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.