CVE-2014-9435 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in Absolut Engine 1.73 allow remote authenticated users to execute arbitrary SQL commands via the (1) sectionID parameter to admin/managersection.php (2) userID parameter to admin/edituser.php (3) username parameter to admin/admin.php or (4) title parameter to admin/managerrelated.php.
Reference
http://seclists.org/fulldisclosure/2014/Dec/131 http://sroesemann.blogspot.de/2014/12/sroeadv-2014-08.html http://www.securityfocus.com/bid/71822
Share on: