Description
|
|
Several SQL Injection vulnerabilities were identified in MyPHP Forum, which may be exploited by attackers to compromise a system. These flaws exist due to missing input sanitising errors when handling the "fid" (forum.php), "member" (member.php) , "email" (forgot.php), and "nbuser" (include.php) variables, which could be exploited to compromise a vulnerable system using specially crafted SQL commands.
|