vendor:
phpDenora
by:
P. de Brouwer - KnickLighter
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: phpDenora
Affected Version From: 1.4.6
Affected Version To: 1.4.6
Patch Exists: YES
Related CWE: N/A
CPE: a:denorastats:phpdenora
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
phpDenora <= 1.4.6 Multiple SQL Injection Vulnerabilities
In this software, there are multiple SQL Injection vulnerabilities in the file 'line.php'. Although the variables seem to be partially filtered with the use of htmlspecialchars(), practice has proven that these parts are vulnerable.
Mitigation:
Upgrade to the latest version of phpDenora (1.4.7) to fix the vulnerability.