SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, (3) refer_friend.php, (4) print_article.php, or (5) add_comment.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Faq | Softbiz | * | 1.1 (including) |