CVE-2013-4945 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (1) ASPSESSIONIDASSRATTQ (2) TABLE_WIDGET_1 (3) TABLE_WIDGET_2 (4) browserDateTimeInfo or (5) browserNumberInfo cookie parameter to DashBoardGUI.aspx; or the (6) UID parameter to login.aspx.
Reference
http://archives.neohapsis.com/archives/bugtraq/2013-07/0082.html http://www.exploit-db.com/exploits/26806 http://www.securityfocus.com/bid/61147
Share on: