|
Description
|
|
Robert Cooper has reported a vulnerability in rebus:list, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed via the "list_id" GET parameter to list.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
|