SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote malicious users to execute arbitrary SQL commands via the myusername parameter (aka Username field) in a do_login action. NOTE: some of these details are obtained from third party information.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
joe pieruccini mclogin system 1.1 |
||
joe pieruccini mclogin system 1.2 |