CVE-2012-3998 Information

Description

Multiple SQL injection vulnerabilities in Sticky Notes before 0.2.27052012.5 allow remote attackers to execute arbitrary SQL commands via the (1) paste id in admin/modules/mod_pastes.php or (2) show.php (3) user id to admin/modules/mod_users.php (4) project to list.php or (5) session id to show.php.

Reference

http://gitorious.org/sticky-notes/sticky-notes/commit/d97475f07520d61af3d20fbaeb2e9a974c190308 http://lists.fedoraproject.org/pipermail/package-announce/2012-June/083120.html http://lists.fedoraproject.org/pipermail/package-announce/2012-June/083169.html https://bugzilla.redhat.com/show_bug.cgi?id=810928

Share on: