Description
|
|
Multiple vulnerabilities were identified in WEB//NEWS, which may be exploited by remote attackers to execute arbitrary SQL commands. These flaws are due to input validation errors in the "modules/startup.php", "include_this/news.php" and "print.php" scripts that do not properly filter specially crafted "wn_userpw", "cat", "id" and "stof" parameters, which may be exploited by malicious users to conduct SQL injection attacks.
|