SQL Injection Vulnerabilities in StatusNet 1.0 and 1.1.0
CVE-2013-4137 · HIGH Severity
AV:N/AC:L/AU:N/C:P/I:P/A:P
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
Learn more about our Cis Benchmark Audit For Microsoft Sql Server.