CVE-2008-7210P3HIGHCVSS 7.5PoCv0.102009-09-11
CVE-2008-7210 [HIGH] CVE-2008-7210: directory.php in AJchat 0.10 allows remote attackers to bypass input validation and conduct SQL inje
directory.php in AJchat 0.10 allows remote attackers to bypass input validation and conduct SQL injection attacks via a numeric parameter with a value matching the s parameter's hash value, which prevents the associated $_GET["s"] variable from being unset. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017)
nvd