Back to search
CVE-2011-5230
Published: Oct 25, 2012
Modified: Aug 7, 2024
PUBLISHED
Description
Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to sys/login/index or (2) memberLoginName parameter to sys/login/member.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
77736
vdb-entry
x_refsource_OSVDB
seotoaster-loginmodel-sql-injection(71843)
vdb-entry
x_refsource_XF
46881
third-party-advisory
x_refsource_SECUNIA
18246
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now