CVE-2011-0407 Information

Description

SQL injection vulnerability in the store function in _phenotype/system/class/PhenoTypeDataObject.class.php in Phenotype CMS 3.0 allows remote attackers to execute arbitrary SQL commands via a crafted URI as demonstrated by Gallery/gal_id/1/image11.html. NOTE: some of these details are obtained from third party information.

Reference

http://osvdb.org/70308 http://secunia.com/advisories/42837 http://www.htbridge.ch/advisory/sql_injection_in_phenotype_cms.html http://www.securityfocus.com/archive/1/515577/100/0/threaded http://www.securityfocus.com/bid/45700 https://exchange.xforce.ibmcloud.com/vulnerabilities/64538

Share on: