Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tlhunter

#37161of 53,624
7.5Total CVSS
Vulnerabilities · 1
PT-2012-5540
7.5
2012-08-26
Unknown · Neoinvoice · CVE-2012-4673
**Name of the Vulnerable Software and Affected Versions** NeoInvoice (affected versions not specified) **Description** The issue is related to a SQL injection vulnerability in the application/controllers/invoice.php file. This vulnerability might allow remote attackers to execute arbitrary SQL commands via vectors involving the `sort col` variable in the `list items` function. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.