Description
SQL injection vulnerability in links.php in Appalachian State University phpWebSite allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action.
Affected products
- appstate / phpwebsite0.7.3 – 0.7.3
- appstate / phpwebsite0.8.2 – 0.8.2
- appstate / phpwebsite0.8.3 – 0.8.3
- appstate / phpwebsite0.9.3 – 0.9.3
- appstate / phpwebsite0.9.3-1 – 0.9.3-1
- appstate / phpwebsite0.9.3-2 – 0.9.3-2
- appstate / phpwebsite0.9.3-3 – 0.9.3-3
- appstate / phpwebsite0.9.3-4 – 0.9.3-4