CVE-2004-0374 Information
Feb 14, 2021
cve
Description
Interchange before 5.0.1 allows remote attackers to \expose the content of arbitrary variables\ and read or modify sensitive SQL information via an HTTP request ending with the _SQLUSER_\ string.
Reference
http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW http://secunia.com/advisories/11234 http://www.debian.org/security/2004/dsa-471 http://www.icdevgroup.org/pipermail/interchange-announce/2004/000043.html http://www.securityfocus.com/bid/10005 https://exchange.xforce.ibmcloud.com/vulnerabilities/15670 interchange-url-obtain-information(15670)
Share on: