Security Advisory

CVE-2018-18399

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-12-20 22:00:00
Last updated 2024-08-05 11:08:21
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.