CVE-2014-2737
22.04.2014, 14:23
SQL injection vulnerability in the get_active_session function in the KTAPI_UserSession class in webservice/clienttools/services/mdownload.php in KnowledgeTree 3.7.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the u parameter, related to the getFileName function.
Vendor | Product | Version |
---|---|---|
knowledgetree | knowledgetree | 3.5 |
knowledgetree | knowledgetree | 3.5.2 |
knowledgetree | knowledgetree | 3.5.4 |
knowledgetree | knowledgetree | 3.5.4a:a |
knowledgetree | knowledgetree | 3.6 |
knowledgetree | knowledgetree | 𝑥 ≤ 3.7.0.2 |
knowledgetree | knowledgetree | 3.7 |
knowledgetree | knowledgetree | 3.7.0.1 |
𝑥
= Vulnerable software versions