Back to search
CVE-2002-0555
Published: Jun 11, 2002
Modified: Aug 8, 2024
PUBLISHED
Description
IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
4498
vdb-entry
x_refsource_BID
20020411 IBM Informix Web DataBlade: Auto-decoding HTML entities
mailing-list
x_refsource_BUGTRAQ
informix-wbm-sql-decoding(8827)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now