Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Owl_intranet_engine | Owl | 0.7 (including) | 0.7 (including) |
Owl_intranet_engine | Owl | 0.8 (including) | 0.8 (including) |