CVE-2012-5900
17.11.2012, 21:55
Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) OB_ID parameter in a single action to admin/action/objects.php, (2) AREA_ID parameter in a single action to admin/action/areas.php, or (3) start parameter in a show action to admin/action/pdf.php.
Vendor | Product | Version |
---|---|---|
samedia | landshop | 0.9.2 |
𝑥
= Vulnerable software versions
References