CVE-2009-4256 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in cource.php in AlefMentor 2.0 and 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) cont_id and (2) courc_id parameters in a pregled action. NOTE: some of these details are obtained from third party information.
Reference
http://secunia.com/advisories/37626 http://www.exploit-db.com/exploits/10358 https://exchange.xforce.ibmcloud.com/vulnerabilities/54624
Share on: