|
Xoops Remote SQL Injection Vulnerability
Xoops is open-source, freely available web portal software written in object-oriented PHP. It is back-ended by a MySQL database and will run on most Unix and Linux distributions. The script userinfo.php fails to properly sanatize user input supplied to a SQL statement. It is possible to modify the SQL statement, possibly resulting in the disclosure of sensitive information. Error messages reported may leak additional information about the structure of the query. |
|
|
Privacy Statement |