SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute arbitrary SQL commands via the css_str parameter in an edit action.
| Software | From | Fixed in |
|---|---|---|
| powerphlogger / powerphlogger | 2.0.9 | 2.0.9.x |
| powerphlogger / powerphlogger | 2.2.2a | 2.2.2a.x |
| powerphlogger / powerphlogger | 2.2.1 | 2.2.1.x |
| powerphlogger / powerphlogger | - | 2.2.5.x |