CVE-2008-1726
11.04.2008, 19:05
Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kqid parameter to (a) articletext.php and (b) articletextonly.php and the (2) username parameter to (c) logincheck.php.
| Vendor | Product | Version |
|---|---|---|
| myknowledgequest | knowledgequest | 2.6 |
𝑥
= Vulnerable software versions
References