### [CVE-2010-1923](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1923)



### Description
SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.
### POC
#### Reference
- http://packetstormsecurity.org/1005-exploits/web20snfcs-sql.txt
#### Github
No PoCs found on GitHub currently.