SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Friendfinder_module | Xoops | * | 3.3 (including) |