CVE
- Id
- 102699
- CVE No.
- CVE-2017-5879
- Status
- Candidate
- Description
- An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated users via an HTTP GET request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects source_selector.php and the following parameter: src.
- Phase
- Assigned (20170203)
- Votes
- None (candidate not yet proposed)
- Comments