Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) sort_mode parameter to wiki/list_pages.php and the (2) highlight parameter to search/index.php. NOTE: the researcher also reported injection via JavaScript code in the Search box, but this is probably a forced SQL error or other separate primary issue.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
bitweaver bitweaver 1.3.1 |
||
bitweaver bitweaver |
||
bitweaver bitweaver 1.1.1_beta |
||
bitweaver bitweaver 1.2.1 |
||
bitweaver bitweaver 1.3 |