#2 SQL Injection in testlogin.php and infouser.php
open
nobody
None
5
2008-09-02
2008-09-02
Anonymous
No
The $_POST values are not checked before entered in the SQL query, therefore this is a security issue which allows the attacker to use an SQL Injection attack.