Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Corenews | Corenews | * | 2.0.1 (including) |