SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the vps_note parameter to dtcadmin/logPushlet.php. NOTE: this issue was originally part of CVE-2011-3197, but that ID was SPLIT due to different researchers.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-03-20 21:38
Updated : 2014-03-24 16:05
NVD link : CVE-2011-5272
Mitre link : CVE-2011-5272
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
gplhost
- domain_technologie_control