Security Advisory
CVE-2005-0725
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows remote attackers to execute arbitrary SQL commands via the articleid parameter to article.php.