userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the uid parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Xoops |
Xoops |
1.0_rc1 (including) |
1.0_rc1 (including) |
References