Variables $user_email(lostpass.php), $user_email(sub.php,unsub.php),
$user_username(sub.php,unsub.php) are not properly sanitized before being
used in SQL queries. This can be used to evaluate arbitrary SQL expression.
Condition: magic_quotes_gpc = off
--------------PoC/Exploit----------------------
Available at: http://evuln.com/vulns/109/exploit.html
--------------Solution---------------------
No Patch available.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.