SQL injection vulnerability in i-search.php in Michelles L2J Dropcalc 4 and earlier allows remote authenticated users to execute arbitrary SQL commands via the itemid parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
L2j_dropcalc | Michelle | * | 4 (including) |