HIGH
Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to sys/login/index or (2) memberLoginName parameter to sys/login/member
Published Oct 25, 2012
7.5
HIGHCVSS 2.0
EPSS 2.24%
Description
Affected products
Remediation
Metrics
References (5)
Change history (0)
No recorded changes yet.