CVE Vulnerabilities

CVE-2005-4137

Published: Dec 09, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in viewinvoice.php in DRZES HMS 3.2 allows remote attackers to execute arbitrary SQL commands via the invoiceID parameter.

Affected Software

Name Vendor Start Version End Version
Drzes_hms Fad_solutions 3.2 (including) 3.2 (including)

References