CVE-2010-2312 Information

Description

SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to execute arbitrary SQL commands via the state parameter in a listings action.

Reference

http://osvdb.org/65431 http://secunia.com/advisories/40162 http://www.exploit-db.com/exploits/13784

Share on: