Multiple SQL injection vulnerabilities in AlstraSoft AskMe Pro allow remote attackers to execute arbitrary SQL commands via the (1) que_id parameter to forum_answer.php or (2) the cat_id parameter to search.php.
Link | Tags |
---|---|
http://osvdb.org/37096 | vdb entry |
http://osvdb.org/46166 | vdb entry |
http://lostmon.blogspot.com/2007/07/alstrasoft-multiple-products-multiple.html | exploit |
http://osvdb.org/37095 | vdb entry |