Description
|
|
A vulnerability has been identified in PHP121 Instant Messenger, which may be exploited by attackers to execute arbitrary SQL commands. This flaw is due to input validation errors in the "php121login.php" script that does not validate the "php121un" and "php121pw" cookie parameters, which could be exploited by malicious people to conduct SQL injection or local file inclusion attacks.
|