CVE-2013-1349 | openSIS up to 5.2 JAXP ajax.php modname code injection (EDB-30471 / SA55913)
A vulnerability was found in openSIS up to 5.2. It has been rated as critical. This issue affects some unknown processing of the file ajax.php of the component JAXP. The manipulation of the argument modname leads to code injection.
The identification of this vulnerability is CVE-2013-1349. The attack may be initiated remotely. Furthermore, there is an exploit available.