RSS   Vulnerabilities for 'Gq file manager'   RSS

2015-01-02
 
CVE-2014-9445

 

 
SQL injection vulnerability in incl/create.inc.php in Installatron GQ File Manager 0.2.5 allows remote attackers to execute arbitrary SQL commands via the create parameter to index.php. NOTE: this can be leveraged for cross-site scripting (XSS) attacks by creating a file that generates an error. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more information.

 

 >>> Vendor: Installatron 2 Products
Gq file manager
Gatequest file manager


Copyright 2024, cxsecurity.com

 

Back to Top