Multiple SQL injection vulnerabilities in ReciPants 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields.
Link | Tags |
---|---|
http://sourceforge.net/project/shownotes.php?group_id=90737&release_id=234415 | patch |
http://securitytracker.com/id?1009984 | patch vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16024 | vdb entry |
http://secunia.com/advisories/11533 | patch vendor advisory third party advisory |
http://www.securityfocus.com/bid/10250 | patch vdb entry |