CVE-2014-5097 Information

Description

Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) get or (2) set action to rate.php.

Reference

http://packetstormsecurity.com/files/127943/ArticleFR-3.0.4-SQL-Injection.html http://www.securityfocus.com/archive/1/533183/100/0/threaded http://www.securityfocus.com/bid/69307 https://www.htbridge.com/advisory/HTB23225

Share on: