SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary SQL commands via the CAT_ID parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Codeavalanche_news |
Xfairguy |
1.x (including) |
1.x (including) |
References