CVE-2011-4638 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in SpamTitan WebTitan before 3.60 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to login-x.php and allow remote authenticated users to execute arbitrary SQL commands via the (2) bldomain (3) wldomain or (4) temid parameter to urls-x.php.
Reference
http://www.sec-1.com/blog/?p=211 Multiple SQL injection vulnerabilities in SpamTitan WebTitan before 3.60 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to login-x.php and allow remote authenticated users to execute arbitrary SQL commands via the (2) bldomain (3) wldomain or (4) temid parameter to urls-x.php.
Share on: