CVE

Id
42231  
CVE No.
CVE-2009-4796  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order and (2) direction parameters to search.php.  
Phase
Assigned (20100422)  
Votes
None (candidate not yet proposed)  
Comments