CVE-2008-3591
11.08.2008, 23:41
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to index.php.
Vendor | Product | Version |
---|---|---|
21degrees | symphony | 𝑥 ≤ 1.7.01 |
21degrees | symphony | 1.1 |
21degrees | symphony | 1.5 |
21degrees | symphony | 1.5.05 |
21degrees | symphony | 1.5.06 |
21degrees | symphony | 1.6.02 |
21degrees | symphony | 1.7 |
𝑥
= Vulnerable software versions
References