Security Advisory

CVE-2007-2854

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2007-05-24 19:00:00
Last updated 2024-08-07 13:57:53
Assigner mitre
State PUBLISHED

Description

Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) style or (2) langue parameter.