Description
SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Meta Data and Taxonomies Filter (MDTF) PHP Object Injection (1.2.2)
Apache HTTP Server Other Vulnerability (CVE-2003-0245)
WordPress Plugin PhotoSmash Galleries Arbitrary File Upload (1.0.7)
PostgreSQL Other Vulnerability (CVE-2002-1402)
MongoDb Improperly Controlled Sequential Memory Allocation Vulnerability (CVE-2026-8199)