SQL Injection Vulnerabilities in StatusNet 1.0 and 1.1.0

SQL Injection Vulnerabilities in StatusNet 1.0 and 1.1.0

CVE-2013-4137 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.