CVE

Id
8700  
CVE No.
CVE-2004-0272  
Status
Candidate  
Description
SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.  
Phase
Proposed (20040318)  
Votes
ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall  
Comments