CVE-2012-5297 Information

Description

SQL injection vulnerability in edit.asp in Mavili Guestbook as released in November 2007 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Reference

http://archives.neohapsis.com/archives/bugtraq/2012-01/0010.html http://code.google.com/p/maviliguestbook/issues/detail?id=1 http://www.securityfocus.com/bid/51252 https://exchange.xforce.ibmcloud.com/vulnerabilities/72098

Share on: