Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Honeycomb_archive | Quicksquare_development | 3.0 (including) | 3.0 (including) |
Honeycomb_archive_enterprise | Quicksquare_development | 3.0 (including) | 3.0 (including) |