The Postaci frontend for PostgreSQL does not properly filter characters such as semicolons, which could allow remote attackers to execute arbitrary SQL queries via the deletecontact.php program.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Postaci | Umut_gokbayrak | 1.1.2 (including) | 1.1.2 (including) |
Postaci | Umut_gokbayrak | 1.1.3 (including) | 1.1.3 (including) |