SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) vadmin_login or (2) vadmin_pass cookie in a request to goldlink.php.Referenceshttp://www.securityfocus.com/bid/8847http://securityreason.com/securityalert/3302https://exchange.xforce.ibmcloud.com/vulnerabilities/13465http://www.securityfocus.com/archive/1/341760