SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Warforge.news | The_war_forge | 1.0 (including) | 1.0 (including) |