SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.
Link | Tags |
---|---|
http://secunia.com/advisories/14516 | third party advisory patch vendor advisory |
http://www.phpmyfaq.de/advisory_2005-03-06.php | patch vendor advisory |