Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL commands via the m parameter to manager/index.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter in an edit_link action to manager/tools.php. NOTE: some of these details are obtained from third party information.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2009-09-25T22:00:00Z
Updated: 2024-09-16T19:30:05.687Z
Reserved: 2009-09-25T00:00:00Z
Link: CVE-2009-3418
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2009-09-25T22:30:09.313
Modified: 2024-02-14T01:17:43.863
Link: CVE-2009-3418
Redhat
No data.