Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) findfid, (2) id, (3) selectfcat, (4) selectfmon, or (5) selectftag parameter in an images action.
References
Configurations
Information
Published : 2011-02-25 09:00
Updated : 2017-08-16 18:33
NVD link : CVE-2011-1100
Mitre link : CVE-2011-1100
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
pixelpost
- pixelpost