Description
Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp.
Affected products
- alan_ward / a-faq1.0 – 1.0
Updated 6m ago · 4 sources