First published: Wed Feb 21 2007(Updated: )
SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the showonly parameter to index.php, a different vector than CVE-2006-5388.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webspell Webspell | =4.01.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.