Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid parameter to (1) friend.php or (2) article.php.
| Software | From | Fixed in |
|---|---|---|
| phpwebsite / phpwebsite | 0.8.2 | 0.8.2.x |
| phpwebsite / phpwebsite | 0.8.3 | 0.8.3.x |
| phpwebsite / phpwebsite | 0.7.3 | 0.7.3.x |