Secunia Logo
 
CVE Reference: CVE-2004-2474
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-2474

Description:
SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/18233

SAID
  Secunia Advisory: SA13300

OSVDB
  12119

CONFIRM
  http://newsphp.sourceforge.net/changelog/changelog_1.24.txt

BID
  11748


Return to the previous page.