Posnic Stock Management System 1.02 Multiple Vulnerabilities
Multiple SQL Injection vulnerabilities were found in Posnic Stock Management System 1.02. These vulnerabilities can be exploited by malicious people to conduct SQL injection attacks. The vulnerabilities are located in the 'change_password.php', 'forget_pass.php', 'update_sales.php', 'update_customer_details.php', 'update_purchase.php', 'update_supplier.php', 'update_stock.php', 'update_payment.php', 'view_sales.php', 'view_customers.php', 'view_purchase.php', 'view_supplier.php', 'view_product.php' and 'view_payments.php' scripts. Input passed via the 'old_pass', 'name', 'sid', 'searchtxt' parameters to the scripts is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.