SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) newsid and (2) id parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pafiledb | Php_arena | extreme_rc_1 (including) | extreme_rc_1 (including) |
Pafiledb | Php_arena | extreme_rc_2 (including) | extreme_rc_2 (including) |
Pafiledb | Php_arena | extreme_rc_3 (including) | extreme_rc_3 (including) |
Pafiledb | Php_arena | extreme_rc_4 (including) | extreme_rc_4 (including) |
Pafiledb | Php_arena | extreme_rc_5 (including) | extreme_rc_5 (including) |