Unknown · Neoinvoice · CVE-2012-4673
**Name of the Vulnerable Software and Affected Versions**
NeoInvoice (affected versions not specified)
**Description**
The issue is related to a SQL injection vulnerability in the application/controllers/invoice.php file. This vulnerability might allow remote attackers to execute arbitrary SQL commands via vectors involving the `sort col` variable in the `list items` function.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.