HIGH
Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1) MyBox and (2) selectFavorites parameters to (a) quotes.php and the (3) QuoteName and (4) QuoteText parameters to (b) quotesadd.php
Published Mar 5, 2009
7.5
HIGHCVSS 2.0
EPSS 0.91%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.