CVE-2010-3467

Publication date

2010-09-17 19:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial module is enabled, allows remote attackers to execute arbitrary SQL commands via the secid parameter in a listarticles action.