CVE-2014-4736
24.07.2014, 14:55
SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process.
Vendor | Product | Version |
---|---|---|
blogengine | e2 | 𝑥 ≤ 2.4 |
𝑥
= Vulnerable software versions
References