daojian1/Nero-Social-Networking-Site-V1.0_005

daojian1/Nero-Social-Networking-Site-V1.0_005

Releases0
Nero Social Networking Site V1.0 profilefriends.php SQL injection

CVE History

CVEPublishedCVSS v3CVSS v2
6.3 MEDIUM6.5 MEDIUM

A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function of the file /profilefriends.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.