CVE-2015-7299
21.10.2015, 18:59
SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter.
Vendor | Product | Version |
---|---|---|
nintex | k2_blackpearl | 4.6.7 |
nintex | k2_for_sharepoint | 4.6.7 |
nintex | k2_smartforms | 4.6.7 |
𝑥
= Vulnerable software versions
References