Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to categoria.php.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-03-15T21:00:00

Updated: 2024-08-07T07:08:38.208Z

Reserved: 2010-03-15T00:00:00

Link: CVE-2009-4698

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-03-15T21:30:00.527

Modified: 2017-09-19T01:30:02.407

Link: CVE-2009-4698

cve-icon Redhat

No data.