A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function of the file /profilefriends.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
| Software | From | Fixed in |
|---|---|---|
| fabian / nero_social_networking_site | 1.0 | 1.0.x |