PHP.news.php.NEWSID.Parameter.SQL.Injection

description-logoDescription

This indicates a SQL injection vulnerability in FlexPHPNews 0.0.5. This issue is due to input validation errors in the "news.php" script when processing the "newsid" parameter. It allows remote attackers to execute arbitrary SQL commands.

affected-products-logoAffected Products

FlexPHPNews 0.0.5

Impact logoImpact

SQL Injection.

recomended-action-logoRecommended Actions

Currently we are not aware of any official supplied fix for issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)