CVE-2008-5165 Information

Description

Multiple SQL injection vulnerabilities in eTicket 1.5.7 allow remote attackers to execute arbitrary SQL commands via the pri parameter to (1) index.php (2) open.php (3) open_raw.php and (4) newticket.php.

Reference

http://secunia.com/advisories/30877 http://www.digitrustgroup.com/advisories/web-application-security-eticket2.html http://www.eticketsupport.com/announcements/170_is_in_the_building-t91.0.html http://www.securityfocus.com/bid/29973 http://www.securitytracker.com/id?1020379 https://exchange.xforce.ibmcloud.com/vulnerabilities/43398

Share on: