CVE
- Id
- 26370
- CVE No.
- CVE-2007-3013
- Status
- Candidate
- Description
- SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to execute arbitrary SQL commands via the id parameter to admin/picture/picture_real_edit.asp, and probably other unspecified vectors.
- Phase
- Assigned (20070604)
- Votes
- None (candidate not yet proposed)
- Comments