CVE-2011-0434

Publication date 7 March 2011

Last updated 24 July 2024


Ubuntu priority

Description

Multiple SQL injection vulnerabilities in Domain Technologie Control (DTC) before 0.32.9 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) admin/bw_per_month.php or (2) client/bw_per_month.php.

Status

Package Ubuntu Release Status
dtc 10.10 maverick
Fixed 0.30.18-1ubuntu1
10.04 LTS lucid
Fixed 0.30.10-1ubuntu1
9.10 karmic
Fixed 0.29.17-1+lenny1build0.9.10.1
8.04 LTS hardy
Fixed 0.25.3-2ubuntu1.1
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities