userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the uid parameter.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Xoops | Xoops | 1.0_rc1 (including) | 1.0_rc1 (including) |
References