A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resulting in injection around the escape of magic quotes.
References
Link Resource
https://github.com/8test/pentest/issues/2 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-03-28T21:42:18

Updated: 2019-03-28T21:42:18

Reserved: 2019-03-28T00:00:00


Link: CVE-2019-10262

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-03-28T22:29:00.793

Modified: 2019-03-29T17:51:32.030


Link: CVE-2019-10262

JSON object: View

cve-icon Redhat Information

No data.

CWE