Title : JGS-Treffen "view_id" Parameter Remote SQL Injection Vulnerability VUPEN ID : VUPEN/ADV-2008-1054 CVE ID : CVE-2008-1640
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-01
Technical Description
A vulnerability has been identified in JGS-Treffen, which could be exploited by attackers to manipulate and inject SQL queries. This issue is caused by an input validation error in the "jgs_treffen.php" script when processing the "view_id" parameter, which could be exploited by malicious people to conduct SQL injection attacks and gain knowledge of sensitive information.