SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.
| Software | From | Fixed in |
|---|---|---|
| freeradius / freeradius | 1.0.2 | 1.0.2.x |