CVE

Id
104110  
CVE No.
CVE-2017-7290  
Status
Candidate  
Description
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.  
Phase
Assigned (20170328)  
Votes
None (candidate not yet proposed)  
Comments