Description
|
|
Multiple vulnerabilities have been identified in PHPEcho CMS, which could be exploited by remote attackers to inject arbitrary SQL queries. These issues are caused by input validation errors in the "modules/admin/modules/gallery.php" script that does not validate user-supplied parameters (e.g. "id") before being used in SQL statements, which could be exploited by malicious users to conduct SQL injection attacks and gain elevated privileges.
|