SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands via the forumid parameter in (1) showcat.php and (2) add.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Saphplesson | Saphp | 1.1 (including) | 1.1 (including) |
Saphplesson | Saphp | 2.0 (including) | 2.0 (including) |