SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Phpnews |
Phpnews |
1.2.3 (including) |
1.2.3 (including) |
References