Total vulnerabilities in the database
Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to wiki/list_pages.php and the (2) highlight parameter to search/index.php. NOTE: the researcher also reported injection via JavaScript code in the Search box, but this is probably a forced SQL error or other separate primary issue.
Software | From | Fixed in |
---|---|---|
bitweaver / bitweaver | 1.3 | 1.3.x |
bitweaver / bitweaver | 1.2.1 | 1.2.1.x |
bitweaver / bitweaver | - | 2.0.0.x |
bitweaver / bitweaver | 1.3.1 | 1.3.1.x |
bitweaver / bitweaver | 1.1.1_beta | 1.1.1_beta.x |