Security Advisory

CVE-2012-4673

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-08-26 01:00:00
Last updated 2024-09-16 22:41:34
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SQL injection vulnerability in application/controllers/invoice.php in NeoInvoice might allow remote attackers to execute arbitrary SQL commands via vectors involving the sort_col variable in the list_items function, a different vulnerability than CVE-2012-3477.