Description
SQL injection vulnerability in list.php in phpRechnung before 1.6.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
References (4)
Core 4
Core References
Vendor Advisory third-party-advisory
x_refsource_jvn
http://jvn.jp/en/jp/JVN02671769/index.html
Various Sources x_refsource_confirm
https://mail.loenshotel.de/phpRechnung/ChangeLog.php
Patch x_refsource_confirm
http://sourceforge.net/projects/phprechnung/files/phpRechnung/1.6.5/phpRechnung_1_6_5.tar.bz2/download
Vendor Advisory third-party-advisory
x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2015-000154
Scores
EPSS
0.0106
EPSS Percentile
61.0%
Details
CWE
CWE-89
Status
published
Products (1)
loenshotel/phprechnung
< 1.6.4
Published
Oct 11, 2015
Tracked Since
Feb 18, 2026