CVE-2004-1836

Publication date

2005-05-10 04:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.