CVE-2011-0434

Domain Technologie Control < 0.32.9 - SQL Injection via cid Parameter

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Domain Technologie Control (DTC) before 0.32.9 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) admin/bw_per_month.php or (2) client/bw_per_month.php.

References (9)

Core 9
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43523
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0556
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/65895
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2179
Patch mailing-list x_refsource_mlist
http://www.gplhost.sg/lists/dtcannounce/msg00025.html

Scores

EPSS 0.0161
EPSS Percentile 73.4%

Details

CWE
CWE-89
Status published
Products (35)
gplhost/domain_technologie_control 0.24.6
gplhost/domain_technologie_control 0.25.1
gplhost/domain_technologie_control 0.25.2
gplhost/domain_technologie_control 0.25.3
gplhost/domain_technologie_control 0.26.7
gplhost/domain_technologie_control 0.26.8
gplhost/domain_technologie_control 0.26.9
gplhost/domain_technologie_control 0.27.3
gplhost/domain_technologie_control 0.28.2
gplhost/domain_technologie_control 0.28.3
... and 25 more
Published Mar 07, 2011
Tracked Since Feb 18, 2026