Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.
Link | Tags |
---|---|
http://pridels0.blogspot.com/2005/12/honeycomb-archive-honeycomb-archive.html | |
http://www.attrition.org/pipermail/vim/2006-March/000580.html | mailing list |
http://www.osvdb.org/21827 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/23829 | vdb entry |
http://secunia.com/advisories/18127 | third party advisory |
http://www.securityfocus.com/bid/15995 | vdb entry |