Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-10-11 15:55
Updated : 2013-10-15 07:42
NVD link : CVE-2013-4137
Mitre link : CVE-2013-4137
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
status
- statusnet