Multiple SQL injection vulnerabilities in Land Down Under (LDU) v701 allow remote attackers to execute arbitrary SQL commands or obtain the installation path via parameters including (1) s, w, and d in users.php, (2) id in comments.php, (3) rusername in auth.php, or (4) h in plug.php.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/17912 | vdb entry |
http://www.neocrome.net/index.php?m=single&id=91 | |
http://www.osvdb.org/11300 | vdb entry |
http://www.securityfocus.com/bid/11569 | vdb entry |
http://secunia.com/advisories/13034 | third party advisory vendor advisory |
http://www.osvdb.org/11299 | vdb entry |
http://www.osvdb.org/11301 | vdb entry |
http://securitytracker.com/id?1012015 | vdb entry |
http://www.neocrome.net/page.php?id=1573 | |
http://www.ptsecurity.ru/advisory.asp | |
http://www.osvdb.org/11302 | vdb entry |