SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote authenticated users to execute arbitrary SQL commands via the database_name parameter.
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Domain_technologie_control | Gplhost | * | 0.32.7 (including) |
Domain_technologie_control | Gplhost | 0.24.6 (including) | 0.24.6 (including) |
Domain_technologie_control | Gplhost | 0.25.1 (including) | 0.25.1 (including) |
Domain_technologie_control | Gplhost | 0.25.2 (including) | 0.25.2 (including) |
Domain_technologie_control | Gplhost | 0.25.3 (including) | 0.25.3 (including) |
Domain_technologie_control | Gplhost | 0.26.7 (including) | 0.26.7 (including) |
Domain_technologie_control | Gplhost | 0.26.8 (including) | 0.26.8 (including) |
Domain_technologie_control | Gplhost | 0.26.9 (including) | 0.26.9 (including) |
Domain_technologie_control | Gplhost | 0.27.3 (including) | 0.27.3 (including) |
Domain_technologie_control | Gplhost | 0.28.2 (including) | 0.28.2 (including) |
Domain_technologie_control | Gplhost | 0.28.3 (including) | 0.28.3 (including) |
Domain_technologie_control | Gplhost | 0.28.4 (including) | 0.28.4 (including) |
Domain_technologie_control | Gplhost | 0.28.6 (including) | 0.28.6 (including) |
Domain_technologie_control | Gplhost | 0.28.9 (including) | 0.28.9 (including) |
Domain_technologie_control | Gplhost | 0.28.10 (including) | 0.28.10 (including) |
Domain_technologie_control | Gplhost | 0.29.1 (including) | 0.29.1 (including) |
Domain_technologie_control | Gplhost | 0.29.6 (including) | 0.29.6 (including) |
Domain_technologie_control | Gplhost | 0.29.8 (including) | 0.29.8 (including) |
Domain_technologie_control | Gplhost | 0.29.10 (including) | 0.29.10 (including) |
Domain_technologie_control | Gplhost | 0.29.14 (including) | 0.29.14 (including) |
Domain_technologie_control | Gplhost | 0.29.15 (including) | 0.29.15 (including) |
Domain_technologie_control | Gplhost | 0.29.16 (including) | 0.29.16 (including) |
Domain_technologie_control | Gplhost | 0.29.17 (including) | 0.29.17 (including) |
Domain_technologie_control | Gplhost | 0.30.6 (including) | 0.30.6 (including) |
Domain_technologie_control | Gplhost | 0.30.8 (including) | 0.30.8 (including) |
Domain_technologie_control | Gplhost | 0.30.10 (including) | 0.30.10 (including) |
Domain_technologie_control | Gplhost | 0.30.18 (including) | 0.30.18 (including) |
Domain_technologie_control | Gplhost | 0.30.20 (including) | 0.30.20 (including) |
Domain_technologie_control | Gplhost | 0.32.1 (including) | 0.32.1 (including) |
Domain_technologie_control | Gplhost | 0.32.2 (including) | 0.32.2 (including) |
Domain_technologie_control | Gplhost | 0.32.3 (including) | 0.32.3 (including) |
Domain_technologie_control | Gplhost | 0.32.4 (including) | 0.32.4 (including) |
Domain_technologie_control | Gplhost | 0.32.5 (including) | 0.32.5 (including) |
Domain_technologie_control | Gplhost | 0.32.6 (including) | 0.32.6 (including) |
Dtc | Ubuntu | lucid | * |