SQL injection vulnerability in SIPhone Enterprise PBX allows remote attackers to execute arbitrary SQL commands via the Username.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1513
Reference (s):
- http://packetstormsecurity.com/files/130194/SIPhone-Enterprise-PBX-SQL-Injection.html
- XF:siphonepbx-username-sql-injection(100582)
- URL: https://exchange.xforce.ibmcloud.com/vulnerabilities/100582

