Beveiligingsadvies

CVE-2008-3591

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2008-08-11 23:00:00
Laatst bijgewerkt 2024-08-07 09:45:18
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to index.php.