SQL injection vulnerability in login.php in Ruperts News allows remote attackers to execute arbitrary SQL commands via the username parameter. Successful exploitation requires that magic_quotes_gpc is set to off.
Publication date: Tue, 02 May 2006 15:02:00 +0000