CVE-2009-4720 Information

Description

SQL injection vulnerability in cgi-bin/gnudip.cgi in GnuDIP 2.1.1 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

Reference

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=539452 http://osvdb.org/56675 http://secunia.com/advisories/36115

Share on: