CVE-2009-4698

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
15/03/2010
Last modified:
19/09/2017

Description

Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to categoria.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:alexandre_amaral:xoops_celepar:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:*:*:*:*:*:*:*:*