SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/21516 | vdb entry exploit |
http://securityreason.com/securityalert/2025 | third party advisory |
http://www.securityfocus.com/archive/1/453964/100/0/threaded | mailing list |