Description
SQL injection vulnerability in search.php Attachmax Dolphin 2.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a Search action to index.php. NOTE: some of these details are obtained from third party information.
Affected products
- attachmax / dolphin2.1.0 – 2.1.0
References
- MISChttp://e-rdc.org/v1/news.php?readmore=108
- VENDOR_ADVISORYhttp://secunia.com/advisories/31794
- EXPLOIThttps://www.exploit-db.com/exploits/6468
- MISChttp://www.securityfocus.com/archive/1/496427/100/0/threaded
- MISChttp://www.securityfocus.com/bid/31207
- MISChttp://osvdb.org/48270
- MISChttp://securityreason.com/securityalert/4307