High
CVSS 7.5
Overview
SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkClick.aspx.
SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 thro...
SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkClick.aspx.
This vulnerability is rated 🟠 HIGH.
Recommended actions: