Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL commands via the m parameter to manager/index.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter in an edit_link action to manager/tools.php. NOTE: some of these details are obtained from third party information.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2009-09-25T22:00:00Z

Updated: 2024-09-16T19:30:05.687Z

Reserved: 2009-09-25T00:00:00Z

Link: CVE-2009-3418

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2009-09-25T22:30:09.313

Modified: 2024-02-14T01:17:43.863

Link: CVE-2009-3418

cve-icon Redhat

No data.