CVE Database
/

CVE-2010-1704

Back to search

CVE-2010-1704

Published: May 4, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to execute arbitrary SQL commands via (1) the password field to login.php, (2) the login field (aka email parameter) to login.php, (3) the password field (aka pass parameter) to the default URI under admin/, and possibly (4) the login field to the default URI under admin/. NOTE: some of these details are obtained from third party information.

VendorProductVersions

n/a

n/a

affected
n/a

References

polls-login-sql-injection(58189)
vdb-entry
x_refsource_XF
aps-login-sql-injection(58127)
vdb-entry
x_refsource_XF
39745
vdb-entry
x_refsource_BID
39622
third-party-advisory
x_refsource_SECUNIA
12395
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now