SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Phpnews | Phpnews | 1.2.5 (including) | 1.2.5 (including) |