SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
References
Configurations
Information
Published : 2007-03-03 12:19
Updated : 2018-10-16 09:37
NVD link : CVE-2007-1250
Mitre link : CVE-2007-1250
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
angel_learning
- learning_management_suite