SQL Injection Vulnerability in LinPHA 0.9.4 session.php Allows Remote Code Execution and Authentication Bypass

SQL Injection Vulnerability in LinPHA 0.9.4 session.php Allows Remote Code Execution and Authentication Bypass

CVE-2004-2066 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.

Learn more about our User Device Pen Test.