← Back

CVE-2011-5039

nvd nist
Published: Dec 30, 2011Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to login.php, (3) the filter parameter to widget.dokumenti_lista.php, and (4) the fin_nalog_id parameter to nalozi_naslov.php.

Affected (1)

1 product
Biznis Heroj
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (8)

Timeline

No history available yet.