SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.
| Software | From | Fixed in |
|---|---|---|
phpmyfaq / phpmyfaq
|
1.4 | 1.4.x |
phpmyfaq / phpmyfaq
|
1.4_alpha1 | 1.4_alpha1.x |
phpmyfaq / phpmyfaq
|
1.5 | 1.5.x |
phpmyfaq / phpmyfaq
|
1.4_alpha2 | 1.4_alpha2.x |
phpmyfaq / phpmyfaq
|
1.4a | 1.4a.x |