SQL injection vulnerability in the insert function in application/controllers/admin/dataentry.php in LimeSurvey 2.06+ allows remote authenticated users to execute arbitrary SQL commands via the closedate parameter.
References
Configurations
History
21 Nov 2024, 02:32
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/75440 - | |
References | () https://bugs.limesurvey.org/plugin.php?page=Source/view&id=15509 - | |
References | () https://bugs.limesurvey.org/view.php?id=9720 - | |
References | () https://github.com/LimeSurvey/LimeSurvey/commit/65d717415a271242b9a30a5330d4eabac1c1a837 - |
Information
Published : 2015-06-28 14:59
Updated : 2024-11-21 02:32
NVD link : CVE-2015-5078
Mitre link : CVE-2015-5078
CVE.ORG link : CVE-2015-5078
JSON object : View
Products Affected
limesurvey
- limesurvey
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')