Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Th3.R00K

#27018of 53,630
9.3Total CVSS
Vulnerabilities · 1
PT-2007-7303
9.3
2007-12-20
Phprpg · Phprpg · CVE-2007-6469
**Name of the Vulnerable Software and Affected Versions** phpRPG version 0.8 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is possible via the `username` parameter in index.php when magic quotes gpc is disabled. **Recommendations** For phpRPG version 0.8, consider enabling magic quotes gpc to prevent SQL injection attacks. As a temporary workaround, restrict access to the index.php file or avoid using the `username` parameter until a patch is available.