CVE-2011-5276
Domain Technologie Control < 0.32.11 - Authenticated SQL Injection via database_name Parameter
Title source: llmDescription
SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote authenticated users to execute arbitrary SQL commands via the database_name parameter.
References (4)
Core 4
Core References
Various Sources x_refsource_confirm
http://git.gplhost.com/gitweb/?p=dtc.git%3Ba=commitdiff%3Bh=541d8457a6989a1a925bb866ed972a5f07c2de64
Various Sources x_refsource_confirm
http://git.gplhost.com/gitweb/?p=dtc.git%3Ba=blob%3Bf=debian/changelog%3Bh=dec9970db76b82295e9003ca34cecab8d629da4f%3Bhb=65a7a1b166ea3c4325efd4da80a78498c829aa5a
Issue Tracking x_refsource_confirm
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=637632
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2011/dsa-2365
Scores
EPSS
0.0106
EPSS Percentile
61.0%
Details
CWE
CWE-89
Status
published
Products (34)
gplhost/domain_technologie_control
0.24.6
gplhost/domain_technologie_control
0.25.1
gplhost/domain_technologie_control
0.25.2
gplhost/domain_technologie_control
0.25.3
gplhost/domain_technologie_control
0.26.7
gplhost/domain_technologie_control
0.26.8
gplhost/domain_technologie_control
0.26.9
gplhost/domain_technologie_control
0.27.3
gplhost/domain_technologie_control
0.28.2
gplhost/domain_technologie_control
0.28.3
... and 24 more
Published
Mar 21, 2014
Tracked Since
Feb 18, 2026