SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject arbitrary SQL commands via the id parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lushinews | Lushinews | 1.00 (including) | 1.00 (including) |
Lushinews | Lushinews | 1.01 (including) | 1.01 (including) |