Multiple SQL injection vulnerabilities in main.php in Chipmailer 1.09 allow remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by (1) anfang, (2) name, (3) mail, (4) anrede, (5) vorname, (6) nachname, (7) gebtag, (8) gebmonat, and (9) gebjahr.
Link | Tags |
---|---|
http://secunia.com/advisories/20643 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27158 | vdb entry |
http://www.vupen.com/english/advisories/2006/2359 | vdb entry |
http://www.securityfocus.com/bid/18463 | vdb entry |
http://marc.info/?l=bugtraq&m=115024576618386&w=2 | mailing list |
http://securitytracker.com/id?1016315 | vdb entry |