Description
|
|
Multiple vulnerabilities were identified in Oneplug CMS, which may be exploited by remote attackers to execute arbitrary SQL commands. These flaws are due to input validation errors in the "press/details.asp", "services/details.asp" and "products/details.asp" scripts that do not properly validate the "Press_Release_ID", "Service_ID" and "Product_ID" parameters, which may be exploited by malicious people to conduct SQL injection attacks.
|