CVE-2009-1810 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php and allow remote authenticated users to execute arbitrary SQL commands via the ID parameter in a Detail action to (2) kategorie.php (3) medium.php (4) person.php or (5) schlagwort.php in modules/ related to classes/class.perform.php.
Reference
http://secunia.com/advisories/35111 http://www.collector.ch/drupal5/?q=node/39 http://www.securityfocus.com/bid/34997 http://www.vupen.com/english/advisories/2009/1344 https://www.exploit-db.com/exploits/8707
Share on: