SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/7253 | vdb entry |
http://www.securityfocus.com/archive/1/219178 | mailing list |
http://www.securityfocus.com/bid/3411 | vdb entry |