CVE-2008-6028 Information

Description

SQL injection vulnerability in list.php in University of Queensland Library Fez 1.3 and 2.0 RC1 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter in a subject action.

Reference

http://www.securityfocus.com/bid/31324 http://www.vupen.com/english/advisories/2008/2652 https://exchange.xforce.ibmcloud.com/vulnerabilities/45332 https://www.exploit-db.com/exploits/6535

Share on: