[原文]SQL injection vulnerability in include/includes/user/login.php in ilchClan before 1.05g allows remote attackers to execute arbitrary SQL commands via the login_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ilchClan contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login.php script not properly sanitizing user-supplied input to the login_name variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
Upgrade to version 1.0.5 G or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.