Multiple SQL injection vulnerabilities in Freeway before 1.4.3.210 allow remote attackers to execute arbitrary SQL commands via unspecified vectors involving the (1) advanced search result and (2) service resource pages.
| Software | From | Fixed in |
|---|---|---|
| openfreeway / freeway | 1.4.0.171 | 1.4.0.171.x |
| openfreeway / freeway | 1.4.1 | 1.4.1.x |
| openfreeway / freeway | 1.0.59 | 1.0.59.x |
| openfreeway / freeway | 1.3.2.160 | 1.3.2.160.x |
| openfreeway / freeway | 1.1.1.80 | 1.1.1.80.x |
| openfreeway / freeway | 1.4 | 1.4.x |
| openfreeway / freeway | 1.3.1.142 | 1.3.1.142.x |
| openfreeway / freeway | 1.4.1.197 | 1.4.1.197.x |
| openfreeway / freeway | 1.3.2.154 | 1.3.2.154.x |
| openfreeway / freeway | 1.3.2.160-joomla_beta | 1.3.2.160-joomla_beta.x |
| openfreeway / freeway | 1.3 | 1.3.x |
| openfreeway / freeway | 1.4.1.171 | 1.4.1.171.x |
| openfreeway / freeway | - | 1.4.2.197.x |
| openfreeway / freeway | 1.3.1.147 | 1.3.1.147.x |
| openfreeway / freeway | 1.3.0.142 | 1.3.0.142.x |
| openfreeway / freeway | 1.0.25 | 1.0.25.x |
| openfreeway / freeway | 1.0.060 | 1.0.060.x |
| openfreeway / freeway | 1.1.1.76 | 1.1.1.76.x |
| openfreeway / freeway | 1.1.1.81 | 1.1.1.81.x |
| openfreeway / freeway | 1.2.0.113 | 1.2.0.113.x |
| openfreeway / freeway | 1.0.25-public_beta | 1.0.25-public_beta.x |