CVE

Id
78853  
CVE No.
CVE-2015-1576  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands via the name parameter to (1) copy2.php, (2) localize.php, (3) metai.php, (4) nc.php, (5) new2.php, or (6) rename2.php in u5admin/; (7) c parameter to u5admin/editor.php; (8) typ parameter to u5admin/meta2.php; or (9) newname parameter to u5admin/rename2.php.  
Phase
Assigned (20150211)  
Votes
None (candidate not yet proposed)  
Comments