CVE-2011-3838 Information

Description

Multiple SQL injection vulnerabilities in Wuzly 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to fp.php (2) epage parameter to newpage.php (3) epost parameter to newpost.php and (4) username parameter to login.php in admin/; or the (5) username parameter to mobile/login.php.

Reference

http://osvdb.org/77915 http://osvdb.org/77916 http://osvdb.org/77917 http://osvdb.org/77918 http://osvdb.org/77919 http://secunia.com/advisories/46163 http://secunia.com/secunia_research/2011-88/ https://exchange.xforce.ibmcloud.com/vulnerabilities/71904

Share on: