CVE-2014-4736
EUVD-2014-465524.07.2014, 14:55
SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| blogengine | e2 | 𝑥 ≤ 2.4 |
𝑥
= Vulnerable software versions
References