HIGH
Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters to search.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (4) msg and (5) password parameters to admin.php
Published Jan 15, 2008
7.5
HIGHCVSS 2.0
EPSS 1.15%
Description
Affected products
Remediation
Metrics
References (6)
Change history (0)
No recorded changes yet.