SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pwsphp | Pwsphp | * | 1.2.3 (including) |