Описание
SQL injection vulnerability in index.php in Synchroweb Technology SynConnect 2.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter in a logoff action.
SQL injection vulnerability in index.php in Synchroweb Technology SynConnect 2.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter in a logoff action.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-2690
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83040
- http://archives.neohapsis.com/archives/bugtraq/2013-03/0134.html
- http://osvdb.org/91693
- http://osvdb.org/ref/91/synconnect.txt
- http://packetstormsecurity.com/files/120958/SynConnect-SQL-Injection.html
- http://www.exploit-db.com/exploits/24898
- http://www.securityfocus.com/bid/58711
Связанные уязвимости
nvd
почти 13 лет назад
SQL injection vulnerability in index.php in Synchroweb Technology SynConnect 2.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter in a logoff action.