CVE-2009-4436
28.12.2009, 19:00
Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2) importquestions.asp, and (3) quiztakers.asp, different vectors than CVE-2007-1706.
Vendor | Product | Version |
---|---|---|
activewebsoftwares | ewebquiz | 8.0 |
𝑥
= Vulnerable software versions
References