Description
SQL injection vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to execute arbitrary SQL commands via the title (aka subject) field.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
http://bugs.elvinbts.org/show_bug.php?id=49
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35430
Scores
EPSS
0.0100
EPSS Percentile
59.3%
Details
CWE
CWE-89
Status
published
Products (2)
elvinbts/elvinbts
1.1.0
elvinbts/elvinbts
< 1.2.0
Published
Jun 19, 2009
Tracked Since
Feb 18, 2026