CVE-2008-3887 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the tab parameter in a projects action and (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in a viewuser action.
Reference
http://packetstorm.linuxsecurity.com/0808-exploits/dotproject-sqlxss.txt http://secunia.com/advisories/31681 http://www.securityfocus.com/bid/30924 https://exchange.xforce.ibmcloud.com/vulnerabilities/44771 https://exchange.xforce.ibmcloud.com/vulnerabilities/44772
Share on: