Free Simple Software "download_id" SQL Injection

  Bookmark
 and Share

Free Simple Software is a PHP-based web application. The application is exposed to an SQL injection issue because it fails to adequately sanitize user-supplied input to the "download_id" parameter of the download module.

Ref: http://www.securityfocus.com/archive/1/514863

10.48.33 - CVE: CVE-2010-4298
Platform: Web Application - SQL Injection