CVE-2011-5175 Information

Description

SQL injection vulnerability in search.php in Banana Dance possibly B.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.

Reference

http://packetstormsecurity.org/files/115772/Banana-Dance-CMS-B.2.1-XSS-SQL-Injection.html http://www.bananadance.org/Program-News/Minor-Update-and-New-Theme http://www.doyoubananadance.com/Program-News/Important-Notice-About-SQLi-Exploit

Share on: