Multiple SQL injection vulnerabilities in Direct News 4.9 allow remote attackers to execute arbitrary SQL commands via (1) the setLang parameter in index.php and (2) unspecified search module parameters.
References
Configurations
Information
Published : 2005-12-27 17:03
Updated : 2017-07-19 18:29
NVD link : CVE-2005-4527
Mitre link : CVE-2005-4527
JSON object : View
CWE
Products Affected
direct_news
- direct_news