Details
-
Bug
-
Resolution: Fixed
-
Major
-
2.4, 2.5 M1
-
None
-
security, sql injection
-
Integration
-
Easy
-
Description
URL parameters "classname", "fieldname", "firCol", "secCol" and "input" are concatenated with the SQL query.