Arbitrary SQL Command Execution in Best Practical Solutions RT

Arbitrary SQL Command Execution in Best Practical Solutions RT

CVE-2011-4460 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to execute arbitrary SQL commands by leveraging access to a privileged account.

Learn more about our User Device Pen Test.