Description
Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.
Remediation
References
Related Vulnerabilities
Atlassian Jira CVE-2019-8442 Vulnerability (CVE-2019-8442)
Drupal Core 6.x Denial of Service (6.0 - 6.32)
WordPress Plugin Shortlinks by Pretty Links-Best WordPress Link Tracking SQL Injection (1.6.7)
Magento CVE-2019-8144 Vulnerability (CVE-2019-8144)
Serendipity Improper Access Control Vulnerability (CVE-2016-10082)