CVE-2012-5162
26.09.2012, 00:55
Multiple SQL injection vulnerabilities in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) edit_category_post or (2) enable_category action to index.php.
Vendor | Product | Version |
---|---|---|
osclass | osclass | 𝑥 ≤ 2.3.4 |
𝑥
= Vulnerable software versions
References