Multiple SQL injection vulnerabilities in Maian Support 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) pass parameter to admin/index.php. Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled. This vulnerability may affect earlier versions of Maian, Support as well.
Publication date: Sun, 19 Mar 2006 07:02:00 +0000