CVE-2015-7299
21.10.2015, 18:59
SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter.
| Vendor | Product | Version |
|---|---|---|
| nintex | k2_blackpearl | 4.6.7 |
| nintex | k2_for_sharepoint | 4.6.7 |
| nintex | k2_smartforms | 4.6.7 |
𝑥
= Vulnerable software versions
References