CVE-2013-0123: Askia Askiaweb
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
Multiple SQL injection vulnerabilities in the administration interface in ASKIA askiaweb allow remote attackers to execute arbitrary SQL commands via (1) the nHistoryId parameter to WebProd/pages/pgHistory.asp or (2) the OrderBy parameter to WebProd/pages/pgadmin.asp.
Affected products
- Askia Askiaweb: affected versions not specified
Published 2013-03-21. Last modified 2026-06-16.