NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Newsdaemon |
Sourceforge |
0.21b (including) |
0.21b (including) |
References