Description
PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL commands. Attackers can exploit the unvalidated 'vid' parameter to execute arbitrary database queries and potentially compromise the web application and database management system.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
3.0
Credits
Vulnerability-Lab [Research Team]
References
www.vulnerability-lab.com/get_content.php?id=2295 (Vulnerability Lab Advisory)
www.phpsugar.com/...php-melody-3-0-vulnerability-report-fix/ (Vulnerability Lab Advisory)
www.phpsugar.com/phpmelody.html (Product Homepage)
www.vulncheck.com/...-vulnerability-via-edit-video-parameter (VulnCheck Advisory: PHP Melody 3.0 SQL Injection Vulnerability via Edit Video Parameter)