SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the shownews parameter.
| Software | From | Fixed in |
|---|---|---|
| powie / pnews | 2.08 | 2.08.x |
| powie / pnews | 2.10 | 2.10.x |