SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject arbitrary SQL commands via the id parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Lushinews | Lushinews | 1.00 (including) | 1.00 (including) |
| Lushinews | Lushinews | 1.01 (including) | 1.01 (including) |