CVE

Id
10900  
CVE No.
CVE-2004-2474  
Status
Candidate  
Description
SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.  
Phase
Assigned (20050820)  
Votes
None (candidate not yet proposed)  
Comments