CVE-2018-18399

Publication date

2018-12-20 22:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.