CVE-2011-5183
20.09.2012, 10:55
Multiple SQL injection vulnerabilities in OrderSys 1.6.4 and earlier allow remote attackers to execute arbitrary SQL commands via the where_clause parameter to (1) index.php, (2) index_long.php, or (3) index_short.php in ordering/interface_creator/.
Vendor | Product | Version |
---|---|---|
bioinformatics | ordersys | 𝑥 ≤ 1.6.3 |
bioinformatics | ordersys | 1.5.5 |
bioinformatics | ordersys | 1.5.6 |
bioinformatics | ordersys | 1.6 |
bioinformatics | ordersys | 1.6.1 |
bioinformatics | ordersys | 1.6.2 |
𝑥
= Vulnerable software versions