Description - SQL Injection Vulnerability in RateIt

SQL Injection found in RateIt script.

Exploit
Available
Solution
Not available - check vendor's website

Vulnerable script: rateit.php

Parameter $rateit_id is not properly sanitized before being used in SQL query. This can be used to make any SQL query by injecting arbitrary SQL code.

Condition: magic_quotes_gpc = off

Order Source Code Review

Protect against hacker attacks by source code analysis of a site or web application done by our team.The work will be done by specialists in web application security.