SpoonLabs.Vivvo.Article.Management.PdfVersion.PHP.SQL.Injection

2018-09-27 This signature was removed in version 13.459.

description-logoDescription

A SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter.

affected-products-logoAffected Products

SpoonLabs Vivvo Article Management 3.2

Impact logoImpact

Execute arbitrary SQL commands.

recomended-action-logoRecommended Actions

Apply patch :
http://www.vivvo.net/forums/showthread.php?t=310

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2018-09-27 13.459
Removed