Description
|
|
Multiple vulnerabilities were identified in phpCoin, which may be exploited by remote attackers to execute arbitrary SQL commands. These flaws are due to an input validation error in the "index.php", "login.php", and "mod.php" scripts which do not properly validate user-supplied input in the "search", "phpcoinsessid", "id", "dtopic_id" and "dcat_id" parameters. A remote attacker could exploit this vulnerability to cause arbitrary SQL commands to be executed.
|