CVE-2013-6787
05.12.2013, 18:55
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter.
Vendor | Product | Version |
---|---|---|
chamilo | chamilo_lms | 𝑥 ≤ 1.9.6 |
chamilo | chamilo_lms | 1.8.6.2 |
chamilo | chamilo_lms | 1.8.7 |
chamilo | chamilo_lms | 1.8.7.1 |
chamilo | chamilo_lms | 1.8.8.2 |
chamilo | chamilo_lms | 1.8.8.4 |
chamilo | chamilo_lms | 1.8.8.6 |
chamilo | chamilo_lms | 1.9.0 |
chamilo | chamilo_lms | 1.9.2 |
chamilo | chamilo_lms | 1.9.4 |
𝑥
= Vulnerable software versions
References