Multiple SQL injection vulnerabilities in index.php in SweetRice CMS prior to 0.6.7.1 allow remote malicious users to execute arbitrary SQL commands via (1) the file_name parameter in an attachment action, (2) the post parameter in a show_comment action, (3) the sys-name parameter in an rssfeed action, or (4) the sys-name parameter in a view action.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
basic-cms sweetrice 0.6.7.1 |