SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated users to execute arbitrary SQL commands via the selgroups parameter.
References
Configurations
Information
Published : 2014-11-20 05:55
Updated : 2014-11-24 05:58
NVD link : CVE-2014-8999
Mitre link : CVE-2014-8999
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
xoops
- xoops