Description
|
|
Several vulnerabilities were reported in CMScore, which can be exploited by an attacker to execute arbitrary SQL commands. These vulnerabilities exist due to a missing input sanitising error when handling the "EntryID" (index.php), "searchterm" (index.php) and "username" variables, which could be exploited to compromise a vulnerable system using specially crafted SQL injection commands.
|