vendor:
PHPNS
by:
David Sopas Ferreira a.k.a SmOk3
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: PHPNS
Affected Version From: phpns current version (v1.1)
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:phpns:phpns
Platforms Tested:
2007
PHPNS SQL Injection
An attacker may execute arbitrary SQL statements on the vulnerable system. This may compromise the integrity of your database and/or expose sensitive information.
Mitigation:
Filter metacharacters from user input.