SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linpha | Linpha | 0.9.0 (including) | 0.9.0 (including) |
Linpha | Linpha | 0.9.1 (including) | 0.9.1 (including) |
Linpha | Linpha | 0.9.2 (including) | 0.9.2 (including) |
Linpha | Linpha | 0.9.3 (including) | 0.9.3 (including) |
Linpha | Linpha | 0.9.4 (including) | 0.9.4 (including) |