|
Mambo Open Source contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "id" variable in the "emailfaq.php" script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|