info
discussion
exploit
solution
references
JamesOff QuoteEngine Multiple Parameter Unspecified SQL Injection Vulnerability
Solution:
The vendor has released QuoteEngine 1.2.0 to address this issue:
JamesOff QuoteEngine 1.0
JamesOff quoteengine-1.2.0.tar.gz
http://prdownloads.sourceforge.net/topicengine/quoteengine-1.2.0.tar.g z?download
JamesOff QuoteEngine 1.1
JamesOff quoteengine-1.2.0.tar.gz
http://prdownloads.sourceforge.net/topicengine/quoteengine-1.2.0.tar.g z?download
Privacy Statement
Copyright 2010, SecurityFocus