← Back to CVE List

CVE-2018-18619

Published: 2018-11-29T22:29Z
Last Modified: 2024-11-21T03:56Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in the "page" parameter. NOTE: The product is discontinued. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt