Multiple SQL injection vulnerabilities in Ixprim 1.2 allow remote attackers to execute arbitrary SQL commands via the story_id parameter to ixm_ixpnews.php, and unspecified other vectors.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/455084/100/0/threaded | mailing list |
http://www.vupen.com/english/advisories/2006/5133 | vdb entry |
http://www.securityfocus.com/bid/21710 | vdb entry exploit |
http://secunia.com/advisories/23453 | exploit third party advisory vendor advisory |
http://acid-root.new.fr/poc/16061221.txt | exploit |
http://securityreason.com/securityalert/2073 | third party advisory |