Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://status.net/2013/07/16/security-alert-sql-injection-attack-for-statusnet-1-0-x-and-1-1-x - Patch, Vendor Advisory | |
References | () http://www.openwall.com/lists/oss-security/2013/07/18/5 - |
Information
Published : 2013-10-11 22:55
Updated : 2024-11-21 01:54
NVD link : CVE-2013-4137
Mitre link : CVE-2013-4137
CVE.ORG link : CVE-2013-4137
JSON object : View
Products Affected
status
- statusnet
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')