在DSNewsletter 1.0中存在多个SQL注入漏洞,当magic_quotes_gpc无效时,远程攻击者可通过以下途径执行任意SQL命令:用于(1) include/sub.php,(2) include/confirm.php,或(3) include/unconfirm.php的邮件参数。
在DSNewsletter 1.0中存在多个SQL注入漏洞,当magic_quotes_gpc无效时,远程攻击者可通过以下途径执行任意SQL命令:用于(1) include/sub.php,(2) include/confirm.php,或(3) include/unconfirm.php的邮件参数。