CVE-2010-1867
07.05.2010, 23:00
SQL injection vulnerability in the ArticleAttachment::GetAttachmentsByArticleNumber method in javascript/tinymcs/plugins/campsiteattachment/attachments.php in Campsite 3.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
Vendor | Product | Version |
---|---|---|
campware.org | campsite | 𝑥 ≤ 3.3.5 |
campware.org | campsite | 2.2.2 |
campware.org | campsite | 2.3.3 |
campware.org | campsite | 2.4.3 |
campware.org | campsite | 2.5.2 |
campware.org | campsite | 2.6.0 |
campware.org | campsite | 2.6.1 |
campware.org | campsite | 2.6.9 |
campware.org | campsite | 2.7.0:rc5 |
campware.org | campsite | 3.0.3 |
campware.org | campsite | 3.1.0 |
campware.org | campsite | 3.1.1 |
campware.org | campsite | 3.1.2 |
campware.org | campsite | 3.1.3 |
campware.org | campsite | 3.2.0 |
campware.org | campsite | 3.2.1 |
campware.org | campsite | 3.2.2 |
campware.org | campsite | 3.2.3 |
campware.org | campsite | 3.3.0 |
campware.org | campsite | 3.3.0:rc1 |
campware.org | campsite | 3.3.1 |
campware.org | campsite | 3.3.2 |
campware.org | campsite | 3.3.3 |
campware.org | campsite | 3.3.4 |
𝑥
= Vulnerable software versions
References