CVE-2010-1923 Information

Description

SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.

Reference

http://osvdb.org/64513 http://packetstormsecurity.org/1005-exploits/web20snfcs-sql.txt http://secunia.com/advisories/39761 https://exchange.xforce.ibmcloud.com/vulnerabilities/58583

Share on: