Security Advisory

CVE-2010-5317

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-01-03 11:00:00
Last updated 2024-09-17 00:15:34
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute arbitrary SQL commands via (1) the file_name parameter in an attachment action, (2) the post parameter in a show_comment action, (3) the sys-name parameter in an rssfeed action, or (4) the sys-name parameter in a view action.