Multiple SQL injection vulnerabilities in SergiDs Top Music module 3.0 PR3 and earlier for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the (1) idartist, (2) idsong, and (3) idalbum parameters to modules.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Top_music_module | Sergids | 3.0_pr3 (including) | 3.0_pr3 (including) |