Description
SQL injection vulnerability in the Tasks plugin in Brim 2.0.0, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via an arbitrary field in a search action to index.php.
Exploits
References
cve@mitre.org
http://secunia.com/advisories/31661cve@mitre.org
http://securityreason.com/securityalert/4251cve@mitre.org
http://www.securityfocus.com/bid/30944cve@mitre.org
https://www.exploit-db.com/exploits/6332af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/31661af854a3a-2127-422b-91ae-364da2661108
http://securityreason.com/securityalert/4251af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/30944af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/44789af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/6332