SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers to execute arbitrary SQL commands via the parent parameter.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/417218 | mailing list exploit vendor advisory |
http://www.securityfocus.com/bid/15389 | vdb entry |
http://www.osvdb.org/21023 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/23109 | vdb entry |
http://secunia.com/advisories/17655 | third party advisory vendor advisory |
http://secunia.com/advisories/17505 | third party advisory |