CVE-2005-0932 Information

Description

Multiple SQL injection vulnerabilities in phpCOIN 1.2.1b and earlier allow remote attackers to execute arbitrary SQL commands (1) via the search engine (2) the username or email fields in the \forgotten password\ feature or (3) the domain name in a package order.

Reference

http://www.gulftech.org/?node=research&article_id=00065-03292005 http://www.securityfocus.com/bid/12917

Share on: