Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-0973
Description:Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in oc- includes/osclass/helpers/hSearch.php and (2) findBySlug function oc- includes/osclass/model/Category.php. NOTE: some of these details are obtained from third party information.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-0973
BugTraq ID: 51662
http://www.securityfocus.com/bid/51662
Bugtraq: 20120125 Multiple vulnerabilities in OSclass (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2012-01/0157.html
https://www.htbridge.ch/advisory/multiple_vulnerabilities_in_osclass.html
http://secunia.com/advisories/47697




© 1998-2025 E-Soft Inc. All rights reserved.