Multiple SQL injection vulnerabilities in IP Reg 0.4 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) location_id parameter to locationdel.php and (2) vlan_id parameter to vlanedit.php. NOTE: the vlanview.php and vlandel.php vectors are already covered by CVE-2007-6579.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ip reg ip reg 0.3 |