CVE

Id
10993  
CVE No.
CVE-2004-2567  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in ReciPants 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields.  
Phase
Assigned (20051122)  
Votes
None (candidate not yet proposed)  
Comments