SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL commands and obtain usernames and passwords via the frm_search_in parameter.
| Software | From | Fixed in |
|---|---|---|
| php_ticket / php_ticket | 0.6 | 0.6.x |
| php_ticket / php_ticket | - | 0.71.x |
| php_ticket / php_ticket | 0.5 | 0.5.x |