SQL injection vulnerability in newscomments.php in Alex News-Engine 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
News-engine | Alex | * | 1.5.0 (including) |