SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands via the forumid parameter in (1) showcat.php and (2) add.php.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Saphplesson | Saphp | 1.1 (including) | 1.1 (including) |
| Saphplesson | Saphp | 2.0 (including) | 2.0 (including) |