Multiple SQL injection vulnerabilities in SaphpLesson 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the Find parameter in (a) search.php, and the (2) LID and (3) Rate parameters in (b) misc.php.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2006/1708 | vdb entry |
http://securityreason.com/securityalert/862 | third party advisory |
http://www.securityfocus.com/bid/17848 | vdb entry |
http://www.osvdb.org/25363 | vdb entry |
http://www.osvdb.org/25362 | vdb entry |
http://secunia.com/advisories/20034 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/433052/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26293 | vdb entry |