Interchange before 5.0.1 allows remote attackers to expose the content of arbitrary variables and read or modify sensitive SQL information via an HTTP request ending with the SQLUSER string.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Interchange | Interchange_development_group | 4.8.4 | 4.8.4 |
Interchange | Interchange_development_group | 4.8.1 | 4.8.1 |
Interchange | Interchange_development_group | 4.8.3 | 4.8.3 |
Interchange | Interchange_development_group | 5.0 | 5.0 |
Interchange | Interchange_development_group | 4.8.9 | 4.8.9 |
Interchange | Interchange_development_group | 4.8.6 | 4.8.6 |
Interchange | Interchange_development_group | 4.8.7 | 4.8.7 |
Interchange | Interchange_development_group | 4.8.5 | 4.8.5 |
Interchange | Interchange_development_group | 4.8.8 | 4.8.8 |
Interchange | Interchange_development_group | 4.8.2 | 4.8.2 |