Phase:SQL injection vulnerability in shared/code/cp_functions_downloads.php in Nicola Asuni All In One Control Panel (AIOCP) before 1.3.009 allows remote attackers to execute arbitrary SQL commands via the download_category parameter.
ReferencesCONFIRM:http://sourceforge.net/project/shownotes.php?release_id=477845 | SECUNIA:23726 | URL:http://secunia.com/advisories/23726
Votes:Assigned (Friday, January 12, 2007)
Comments:None (candidate not yet proposed)
F7: