CVE-2013-3523

SQL injection vulnerability in This HTML Is Simple (THIS) before 1.2.4 allows remote to execute arbitrary SQL commands via vectors related to op=page&id= in the URL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gajennings:this:*:a:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.1.8:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:gajennings:this:1.2.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:53

Type Values Removed Values Added
References () http://freecode.com/projects/this/releases/353516 - () http://freecode.com/projects/this/releases/353516 -
References () http://osvdb.org/91976 - () http://osvdb.org/91976 -
References () http://xforce.iss.net/xforce/xfdb/84168 - () http://xforce.iss.net/xforce/xfdb/84168 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/84168 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/84168 -

16 Mar 2022, 16:15

Type Values Removed Values Added
References
  • {'url': 'http://gajennings.net/this/?arg=&op=page&id=2', 'name': 'http://gajennings.net/this/?arg=&op=page&id=2', 'tags': [], 'refsource': 'CONFIRM'}
  • (XF) http://xforce.iss.net/xforce/xfdb/84168 -
Summary SQL injection vulnerability in This HTML Is Simple (THIS) before 1.2.4 allows remote to execute arbitrary SQL commands via unspecified vectors. SQL injection vulnerability in This HTML Is Simple (THIS) before 1.2.4 allows remote to execute arbitrary SQL commands via vectors related to op=page&id= in the URL.

Information

Published : 2013-05-10 21:55

Updated : 2025-04-11 00:51


NVD link : CVE-2013-3523

Mitre link : CVE-2013-3523

CVE.ORG link : CVE-2013-3523


JSON object : View

Products Affected

gajennings

  • this
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')