SQL injection vulnerability in the Admin Panel in Nice PHP FAQ Script (Knowledge base Script) allows remote attackers to execute arbitrary SQL commands via the Password parameter (aka the pass field).
References
Configurations
Information
Published : 2009-03-25 11:30
Updated : 2017-09-28 18:33
NVD link : CVE-2008-6525
Mitre link : CVE-2008-6525
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
nicephpscripts
- nice_php_faq_script