SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pwsphp | Pwsphp | * | 1.2.3 (including) |