Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpyellowtm_lite | Phpyellow | 5.33 (including) | 5.33 (including) |
Phpyellowtm_pro | Phpyellow | 5.33 (including) | 5.33 (including) |