Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to login/member.php or (2) im_receiver parameter to login/imcenter.php.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/14629 | vdb entry exploit |
http://secunia.com/advisories/16531/ | third party advisory |
http://marc.info/?l=bugtraq&m=112474427221031&w=2 | mailing list |