SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value parameter.
References
Link | Resource |
---|---|
http://secunia.com/advisories/56189 | Vendor Advisory |
http://www.opendocman.com/opendocman-v1-2-7-1-release | Patch Vendor Advisory |
http://www.opendocman.com/opendocman-v1-2-7-2-released | Patch Vendor Advisory |
http://www.securityfocus.com/bid/65775 | |
https://www.htbridge.com/advisory/HTB23202 | Exploit |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2014-03-07T20:00:00
Updated: 2014-03-07T19:57:00
Reserved: 2014-02-12T00:00:00
Link: CVE-2014-1945
JSON object: View
NVD Information
Status : Analyzed
Published: 2014-03-09T13:16:57.083
Modified: 2014-03-10T16:24:22.857
Link: CVE-2014-1945
JSON object: View
Redhat Information
No data.
CWE