CVE-2013-0123: Askia Askiaweb

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in the administration interface in ASKIA askiaweb allow remote attackers to execute arbitrary SQL commands via (1) the nHistoryId parameter to WebProd/pages/pgHistory.asp or (2) the OrderBy parameter to WebProd/pages/pgadmin.asp.

Affected products

  • Askia Askiaweb: affected versions not specified

Published 2013-03-21. Last modified 2026-06-16.