CVE-2013-3536 Information

Description

SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and earlier for WHMCS allows remote attackers to execute arbitrary SQL commands via the hash parameter.

Reference

http://packetstormsecurity.com/files/121046/WHMCS-Grouppay-1.5-SQL-Injection.html http://secunia.com/advisories/52804 http://www.exploit-db.com/exploits/24934 http://www.osvdb.org/91980

Share on: