Description: The-0utl4w has reported a vulnerability in
phpHotResources, which can be exploited by malicious people to conduct
SQL injection attacks.
Input passed to the parameter "kind" in cat.php is not properly
sanitised before being used in SQL queries. This can be exploited to
manipulate SQL queries by injecting arbitrary SQL code.
Solution: Edit the source code to ensure that input is properly sanitised.
Provided and/or discovered by: The-0utl4w
Original Advisory: http://forum.aria-security.com/showthread.php?p=70
|