Found by E.Minaev (underwater (at) itdefence (dot) ru [email concealed])
ITDefence.ru
1) SQL Injection in login function. With help of this injection is possible
to make per-symbol brute of tables names of blog's database
(magic_quotes_gpc should be tured off).
------------------------------------------
"$sql = "select * from $tblUsers where login = '$login'";
if ( $login != $row['login'] ) $valid_user = 0;
if ( $password != $row['password'] ) $valid_user = 0;"
------------------------------------------
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.