SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Alex_guestbook | Alexphpteam | 3.12 (including) | 3.12 (including) |
Alex_guestbook | Alexphpteam | 3.13 (including) | 3.13 (including) |
Alex_guestbook | Alexphpteam | 4.0.1 (including) | 4.0.1 (including) |
Alex_guestbook | Alexphpteam | 4.0.2 (including) | 4.0.2 (including) |