11 lines
No EOL
558 B
Text
11 lines
No EOL
558 B
Text
source: https://www.securityfocus.com/bid/14927/info
|
|
|
|
phpMyFAQ is affected by an SQL injection vulnerability. This issue is due to the application failing to properly sanitize user-supplied input before using it in a SQL query.
|
|
|
|
This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
|
|
|
|
phpMyFAQ version 1.5.1 is reported prone to this vulnerability.
|
|
|
|
switch to /admin directory, click on "forgotten password" feature
|
|
user: ' or isnull(1/0) /*
|
|
mail: [your_email] |