Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) style or (2) langue parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bti-tracker | Bti-tracker | * | 1.4.1 (including) |