Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.
Link | Tags |
---|---|
http://www.gulftech.org/?node=research&article_id=00062-01022005 | patch vendor advisory exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18732 | vdb entry |
http://secunia.com/advisories/13697/ | patch vendor advisory third party advisory exploit |
http://marc.info/?l=bugtraq&m=110485682424110&w=2 | mailing list |