CVE-2012-2338 Information

Description

SQL injection vulnerability in includes/picture.class.php in Galette 0.63 0.63.1 0.63.2 0.63.3 and 0.64rc1 allows remote attackers to execute arbitrary SQL commands via the id_adh parameter to picture.php.

Reference

http://redmine.ulysses.fr/issues/250 http://redmine.ulysses.fr/projects/galette/repository/revisions/8c13ec159ba http://www.openwall.com/lists/oss-security/2012/05/10/5 http://www.openwall.com/lists/oss-security/2012/05/11/1 http://www.securityfocus.com/bid/53463

Share on: