CVE-2013-2945
02.04.2014, 16:17
SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL commands via the show_statuses[] parameter. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.
Vendor | Product | Version |
---|---|---|
b2evolution | b2evolution | 𝑥 ≤ 4.1.6 |
b2evolution | b2evolution | 4.1.0 |
b2evolution | b2evolution | 4.1.1 |
b2evolution | b2evolution | 4.1.2 |
b2evolution | b2evolution | 4.1.3 |
b2evolution | b2evolution | 4.1.4 |
b2evolution | b2evolution | 4.1.5 |
𝑥
= Vulnerable software versions
References