CVE-2010-1994
20.05.2010, 17:30
SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the q parameter in conjunction with a /news/search PATH_INFO.
Vendor | Product | Version |
---|---|---|
tomatocms | tomatocms | 𝑥 ≤ 2.0.4 |
tomatocms | tomatocms | 2.0.0 |
tomatocms | tomatocms | 2.0.1 |
tomatocms | tomatocms | 2.0.2 |
tomatocms | tomatocms | 2.0.3 |
tomatocms | tomatocms | 2.0.3.1430 |
tomatocms | tomatocms | 2.0.3.1622 |
𝑥
= Vulnerable software versions
References