SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpmyfaq | Phpmyfaq | 1.4 (including) | 1.4 (including) |
Phpmyfaq | Phpmyfaq | 1.4_alpha1 (including) | 1.4_alpha1 (including) |
Phpmyfaq | Phpmyfaq | 1.4_alpha2 (including) | 1.4_alpha2 (including) |
Phpmyfaq | Phpmyfaq | 1.4a (including) | 1.4a (including) |
Phpmyfaq | Phpmyfaq | 1.5 (including) | 1.5 (including) |