HIGH
Multiple SQL injection vulnerabilities in phpBMS 0.96 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to modules/bms/invoices_discount_ajax.php, (2) f parameter to dbgraphic.php, and (3) tid parameter in a show action to advancedsearch.php
Published Oct 22, 2009
7.5
HIGHCVSS 2.0
EPSS 0.95%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.