CVE-2013-0123

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
21/03/2013
Last modified:
11/04/2025

Description

Multiple SQL injection vulnerabilities in the administration interface in ASKIA askiaweb allow remote attackers to execute arbitrary SQL commands via (1) the nHistoryId parameter to WebProd/pages/pgHistory.asp or (2) the OrderBy parameter to WebProd/pages/pgadmin.asp.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:askia:askiaweb:-:*:*:*:*:*:*:*