CVE
- Id
- 41189
- CVE No.
- CVE-2009-3754
- Status
- Candidate
- Description
- Multiple SQL injection vulnerabilities in phpBMS 0.96 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to modules/bms/invoices_discount_ajax.php, (2) f parameter to dbgraphic.php, and (3) tid parameter in a show action to advancedsearch.php.
- Phase
- Assigned (20091022)
- Votes
- None (candidate not yet proposed)
- Comments