Variable $_POST[username] isn't properly sanitized before being used in a
SQL query. This can be used to make any SQL query by injecting arbitrary
SQL code.
Condition: gpc_magic_quotes - off
Administrator has an ability to import themes using php code insertion from
Admin Control Panel.
System access is possible.
--------------Exploit----------------------
Available at: http://evuln.com/vulns/41/exploit.html
--------------Solution---------------------
No Patch available.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.