SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses module permissions to execute arbitrary SQL commands via the cid parameter.
| Software | From | Fixed in |
|---|---|---|
| bcoos / bcoos | 1.0.10 | 1.0.10.x |
| bcoos / bcoos | 1.0.12 | 1.0.12.x |
| bcoos / bcoos | - | 1.0.13.x |
| bcoos / bcoos | 1.0.11 | 1.0.11.x |
| bcoos / bcoos | 1.0.9 | 1.0.9.x |