|
TSOKA:CMS versions 1.1, 1.9, and 2.0 contain a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the "id" parameter when "pag" is set to "articolo." This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|