Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into parameters in a calculate action, and the (3) id parameter in an edit action to index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
X-changer | Skintech | 0.20 (including) | 0.20 (including) |