SQL injection vulnerability in the Statistics (ke_stats) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in February 2014.
References
Configurations
History
No history.
Information
Published : 2014-10-03 14:55
Updated : 2024-02-04 18:35
NVD link : CVE-2014-6293
Mitre link : CVE-2014-6293
CVE.ORG link : CVE-2014-6293
JSON object : View
Products Affected
kennziffer
- statistics
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')