userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the uid parameter.
Affected Software
| Name |
Vendor |
Start Version |
End Version |
| Xoops |
Xoops |
1.0_rc1 (including) |
1.0_rc1 (including) |
References