Beveiligingsadvies

CVE-2014-9235

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2014-12-03 21:00:00
Laatst bijgewerkt 2024-09-17 00:37:10
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/.