Description
News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID parameter. Attackers can send GET requests to index.php/show/news/ with malicious SQL statements to extract sensitive database information.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Mr Winst0n
References
www.exploit-db.com/exploits/46456 (ExploitDB-46456)
www.phpscriptsmall.com/ (Official Product Homepage)
www.vulncheck.com/...site-script-sql-injection-via-index-php (VulnCheck Advisory: News Website Script 2.0.5 SQL Injection via index.php)