Multiple SQL injection vulnerabilities in the login_user function in yans.func.php in Lucas Rodriguez San Pedro Yet Another News System (YANS) 0.2b allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-11-15 07:07
Updated : 2017-07-19 18:34
NVD link : CVE-2006-5908
Mitre link : CVE-2006-5908
JSON object : View
CWE
Products Affected
lucas_rodriguez_san_pedro
- yet_another_news_system