CVE-2013-7175 Information

Description

Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title (2) File name or (3) Candidate Name field.

Reference

http://osvdb.org/102414 http://www.kb.cert.org/vuls/id/869702 http://www.securityfocus.com/bid/65104

Share on: