The Postaci frontend for PostgreSQL does not properly filter characters such as semicolons, which could allow remote attackers to execute arbitrary SQL queries via the deletecontact.php program.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Postaci | Umut_gokbayrak | 1.1.2 (including) | 1.1.2 (including) |
| Postaci | Umut_gokbayrak | 1.1.3 (including) | 1.1.3 (including) |