SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote malicious users to execute arbitrary SQL commands via the search field to download.php.
source: wwwsecurityfocuscom/bid/14926/info
JPortal is prone to an SQL injection vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may perm ...