Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title, (2) File name, or (3) Candidate Name field.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2014-01-24T02:00:00
Updated: 2024-08-06T18:01:20.016Z
Reserved: 2013-12-19T00:00:00
Link: CVE-2013-7175
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-01-24T04:38:09.637
Modified: 2024-11-21T02:00:26.200
Link: CVE-2013-7175
Redhat
No data.