Multiple SQL injection vulnerabilities in an unspecified BPG-InfoTech Content Management System product allow remote attackers to execute arbitrary SQL commands via the (1) vjob parameter in publications_list.asp or (2) InfoID parameter in publication_view.asp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Content_management_system | Bpg-infotech | * | * |