CVE-2013-2627 Information

Description

SQL injection vulnerability in action.php in Leed (Light Feed) possibly before 1.5 Stable allows remote attackers to execute arbitrary SQL commands via the id parameter in a removeFolder action.

Reference

http://osvdb.org/101156 http://seclists.org/bugtraq/2013/Dec/107 http://www.csnc.ch/misc/files/advisories/CSNC-2013-005-006-007_Leed_Multiple_vulns.txt http://www.securityfocus.com/bid/64426

Share on: