CVE-2009-4865
11.05.2010, 12:02
Multiple SQL injection vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) search_name and (2) languages parameters. NOTE: some of these details are obtained from third party information.
Vendor | Product | Version |
---|---|---|
i-escorts | i-escorts_agency_script | * |
i-escorts | i-escorts_directory_script | * |
𝑥
= Vulnerable software versions
References