Page 2 of 6 results (0.001 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en LetoDMS_Core/Core/inc.ClassDMS.php en LetoDMS (antes MyDMS) en versiones anteriores a la 3.3.8 permiten que atacantes remotos ejecuten comandos SQL arbitrarios mediante vectores no especificados. • http://sourceforge.net/p/mydms/code/HEAD/tree/trunk/CHANGELOG http://www.openwall.com/lists/oss-security/2012/10/06/1 http://www.openwall.com/lists/oss-security/2012/10/31/7 http://www.securityfocus.com/bid/55822 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •