Description
|
|
Mark Stanislav has discovered two vulnerabilities in e-ticketing, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed via the "user_name" and "password" POST parameters to login/loginscript.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerabilities are confirmed in the version downloaded on 2012-04-05. Other versions may also be affected.
|