CVE-2004-1846 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp (2) ID parameter to category_news.asp or (3) filter parameter to news_sort.asp.
Reference
http://marc.info/?l=bugtraq&m=107999733503496&w=2 http://secunia.com/advisories/11180 http://securitytracker.com/id?1009507 http://www.osvdb.org/4495 http://www.osvdb.org/4496 http://www.osvdb.org/4497 http://www.securityfocus.com/bid/9935 https://exchange.xforce.ibmcloud.com/vulnerabilities/15549
Share on: