Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and previous versions allow (1) remote malicious users to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in the gestion_membre.php page to base.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
digitalhive digitalhive |