YourArcadeScript "username" Parameter SQL Injection

Monday, June 7, 2010


YourArcadeScript is a PHP-based web application. The application is exposed to an SQL injection issue because it fails to sufficiently sanitize user-supplied data to the "username" parameter of the "includes/saveregister.php" script before using it in an SQL query. YourArcadeScript version 2.0b1 is affected.

Ref: http://www.securityfocus.com/bid/40459/references

10.23.61 - CVE: Not Available
Platform: Web Application - SQL Injection

1 comments:

Anonymous said...

Version 2.2a does not have this issue.

Most Recent Post

MORE ON ARCHIVE
Widget by Mad Tomato

Help Me Expose This Article in Bulk!

Bookmark & Share

- OR -

SELECT YOUR PREFERRED ONE:

Bookmark and Share