PHP Arenas' paFileDB has been reported prone to an SQL injection vulnerability. This vulnerability is reportedly caused by a lack of sufficient sanitization of user-supplied URI parameters passed to paFileDB. As a result, an attacker may inject SQL instructions by supplying malicious commands embedded within requests to the affected paFileDB.php script.
PHP Arenas' paFileDB has been reported prone to an SQL injection vulnerability. This vulnerability is reportedly caused by a lack of sufficient sanitization of user-supplied URI parameters passed to paFileDB. As a result, an attacker may inject SQL instructions by supplying malicious commands embedded within requests to the affected paFileDB.php script.