Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2013-10-11 22:55
Updated : 2024-02-04 18:16
NVD link : CVE-2013-4137
Mitre link : CVE-2013-4137
CVE.ORG link : CVE-2013-4137
JSON object : View
Products Affected
status
- statusnet
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')