SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these details are obtained from third party information.
| Software | From | Fixed in |
|---|---|---|
limesurvey / limesurvey
|
1.80+ | 1.80+.x |
limesurvey / limesurvey
|
1.72 | 1.72.x |
limesurvey / limesurvey
|
1.85 | 1.85.x |
limesurvey / limesurvey
|
1.53+ | 1.53+.x |
limesurvey / limesurvey
|
- | 1.91\+.x |
limesurvey / limesurvey
|
1.52 | 1.52.x |
limesurvey / limesurvey
|
1.87+ | 1.87+.x |
limesurvey / limesurvey
|
1.86 | 1.86.x |
limesurvey / limesurvey
|
1.90+ | 1.90+.x |
limesurvey / limesurvey
|
1.81+ | 1.81+.x |
limesurvey / limesurvey
|
1.70+ | 1.70+.x |
limesurvey / limesurvey
|
1.50 | 1.50.x |
limesurvey / limesurvey
|
1.71+ | 1.71+.x |
limesurvey / limesurvey
|
1.01 | 1.01.x |
limesurvey / limesurvey
|
1.82+ | 1.82+.x |