SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Snews | Solucija | * | 1.3 (including) |
Snews | Solucija | 1.2 (including) | 1.2 (including) |