SQL injection vulnerability in index.php in ClientExec 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) billshowid, (2) billdetailid, (3) fuse, and (4) frmClientID parameters.
Link | Tags |
---|---|
http://www.clientexec.com/forum/showthread.php?t=8006 | patch |
http://www.osvdb.org/21163 | vdb entry exploit |
http://www.ce-talk.com/showthread.php?t=653 | patch |
http://pridels0.blogspot.com/2005/11/clientexec-2x-multiple-sql-inj.html | |
http://secunia.com/advisories/17756 | exploit third party advisory patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/23271 | vdb entry |
http://www.vupen.com/english/advisories/2005/2628 | vdb entry |