CVE

Id
94220  
CVE No.
CVE-2016-7400  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller action, or (3) content_id parameter in a showComments expComment controller action.  
Phase
Assigned (20160909)  
Votes
None (candidate not yet proposed)  
Comments