CVE

Id
15372  
CVE No.
CVE-2005-4168  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) the username.  
Phase
Assigned (20051211)  
Votes
None (candidate not yet proposed)  
Comments