SQL injection vulnerability in list.php in CityForFree indexcity 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Indexcity | Cityforfree | 1.0 (including) | 1.0 (including) |