Subdreamer 1.0 - SQL Injection

EDB-ID:

25235


Author:

GHC team

Type:

webapps


Platform:

PHP

Date:

2005-03-18


source: https://www.securityfocus.com/bid/12839/info

Subdreamer is prone to an SQL injection vulnerability.

Because of this, a malicious user may influence database queries in order to view or modify sensitive information, potentially compromising the software or the database.

Subdreamer Light is reported to be affected by this issue. All versions of Subdreamer Light are considered to be vulnerable at the moment. 

http://www.example.com/index.php?categoryid=3&p17_sectionid=1&p17_imageid=[SQL code]