WikidForum 2.20 ha SQL Injection attraverso il parent_post_id rpc.php o il parametro num_records, o index.php? Action = cercare il parametro select_sort. |
https://www.exploit-db.com/exploits/45564/ https://seccops.com/wikidforum-2-20-multiple-sql-injection-vulnerabilities/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18075 |
Vulnerabilità: CVE-2018-18075
