SQL injection vulnerability in ADMIN/loginaction.php in WSCreator 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the Email (aka username) parameter.
References
Configurations
History
No history.
Information
Published : 2009-12-17 18:30
Updated : 2018-10-10 19:49
NVD link : CVE-2009-4351
Mitre link : CVE-2009-4351
CVE.ORG link : CVE-2009-4351
JSON object : View
Products Affected
wscreator
- wscreator
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')