LWN.net Logo

ampache: multiple vulnerabilities

Package(s):ampache CVE #(s):CVE-2007-4437 CVE-2007-4438
Created:October 15, 2007 Updated:October 17, 2007
Description: SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match parameter. Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.
Alerts:
Gentoo 200710-13 2007-10-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds