paFileDB SQL injection

Determine if pafiledb is vulnerable to a SQL injection

The remote web server contains a PHP script that is affected by
several SQL injection issues.

The remote installation of paFileDB is vulnerable to SQL injection
attacks because of its failure to sanitize input to the 'id' and
'rating' parameters to the 'pafiledb.php' script. A possible hacker may use
this flaw to control your database.

Unknown at this time.

Medium / CVSS Base Score : 5

Networks Security ID: 7183

Vulnerability Assessment Copyright: This script is Copyright (C) 2003-2006 Renaud Deraison

