Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Corenews | Corenews | * | 2.0.1 (including) |