Описание
Multiple SQL injection vulnerabilities in Pro Publish 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameter to (a) admin/login.php, (3) find_str parameter to (b) search.php, or (4) artid parameter to (c) art.php, or (5) catid parameter to (d) cat.php.
Multiple SQL injection vulnerabilities in Pro Publish 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameter to (a) admin/login.php, (3) find_str parameter to (b) search.php, or (4) artid parameter to (c) art.php, or (5) catid parameter to (d) cat.php.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-2128
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26148
- http://evuln.com/vulns/130/summary.html
- http://secunia.com/advisories/19882
- http://soot.shabgard.org/bugs/propublish.txt
- http://www.osvdb.org/25124
- http://www.osvdb.org/25125
- http://www.osvdb.org/25126
- http://www.osvdb.org/25127
- http://www.securityfocus.com/archive/1/435787/100/0/threaded
- http://www.securityfocus.com/bid/17762
- http://www.vupen.com/english/advisories/2006/1578
Связанные уязвимости
Multiple SQL injection vulnerabilities in Pro Publish 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameter to (a) admin/login.php, (3) find_str parameter to (b) search.php, or (4) artid parameter to (c) art.php, or (5) catid parameter to (d) cat.php.