CVE-2005-3363

SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands via the forumid parameter in (1) showcat.php and (2) add.php.

Date published : 2005-10-29

http://www.securityfocus.com/bid/15185

http://marc.info/?l=bugtraq&m=113018965520240&w=2