Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-3129 (Catviz)

BugsAlert Home > CVE-2008-3129 (Catviz)
 
 

Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL commands via the (1) foreign_key_value paramter in the news page and (2) webpage parameter in the webpage_multi_edit form.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3129

Learn more about CVE-2008-3129 (Catviz)
 
Tags: cve-2008-3129 catviz

Related Items

      VU#111034: GnuTLS Server Name extension Denial of Service

      VU#912593:Guidance EnCase Enterprise uses weak authentication to identify target machines

      CVE-2007-5394 (pagemaker)

      Quick Review: Security Power Tools

      FrSIRT - Drupal Security Update Fixes Multiple Security Bypass Vulnerabilities

      Debian Security Update Fixes HPLIP Command Injection Vulnerbility

      CVE-2008-4384 (lpviewer)

 

Pixel