Kalptaru Infotech Ltd. Star Articles中存在多个SQL注入漏洞。远程攻击者可以借助article.list.php的subcatid参数;article.print.ph,article.comments.php,article.publisher.php,article.download.phpp的artid参数;以及article.download.php的PATH_INFO,注入任意的SQL指令。
Kalptaru Infotech Ltd. Star Articles中存在多个SQL注入漏洞。远程攻击者可以借助article.list.php的subcatid参数;article.print.ph,article.comments.php,article.publisher.php,article.download.phpp的artid参数;以及article.download.php的PATH_INFO,注入任意的SQL指令。