SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Openconf | Zakongroup | 4.00 (including) | 4.00 (including) |
| Openconf | Zakongroup | 4.01 (including) | 4.01 (including) |
| Openconf | Zakongroup | 4.02 (including) | 4.02 (including) |
| Openconf | Zakongroup | 4.10 (including) | 4.10 (including) |
| Openconf | Zakongroup | 4.11 (including) | 4.11 (including) |