MEDIUM
Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to execute arbitrary SQL commands via the SurveyID parameter to survey/ReviewReadOnlySurvey.aspx or (2) remote authenticated users to execute arbitrary SQL commands via the SurveyID parameter to survey/UploadImagePopupToDb.aspx
Published Nov 6, 2014
6.5
MEDIUMCVSS 2.0
EPSS 1.73%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.