CVE-2010-4857 Information

Description

SQL injection vulnerability in click.php in CAG CMS 0.2 Beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter.

Reference

http://packetstormsecurity.org/1010-exploits/cagcms-sqlxss.txt http://securityreason.com/securityalert/8415 http://www.exploit-db.com/exploits/15210 http://www.securityfocus.com/bid/43719 https://exchange.xforce.ibmcloud.com/vulnerabilities/62250

Share on: