Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the login_username parameter to login.php or (2) the item parameter to news.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jasmine_cms | Efstratios_geroulis | 1.0 (including) | 1.0 (including) |