sql injection in dotproject 2.1.5
A SQL injection vulnerability exists in dotproject 2.1.5. An attacker can exploit this vulnerability by sending a maliciously crafted request to the vulnerable application. This can allow the attacker to execute arbitrary SQL commands on the underlying database, potentially allowing them to access sensitive data. The vulnerability is located in the fileviewer.php file, where the application is vulnerable to an unauthenticated SQL injection attack. An attacker can exploit this vulnerability by sending a maliciously crafted request to the vulnerable application. This can allow the attacker to execute arbitrary SQL commands on the underlying database, potentially allowing them to access sensitive data.