SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.
Link | Tags |
---|---|
http://www.phpbb.com/phpBB/viewtopic.php?t=153818 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/13867 | vdb entry |
http://marc.info/?l=bugtraq&m=107196735102970&w=2 | mailing list |
http://www.securityfocus.com/bid/9122 | exploit vdb entry patch vendor advisory |
http://marc.info/?l=bugtraq&m=107005608726609&w=2 | mailing list |
http://marc.info/?l=bugtraq&m=106997132425576&w=2 | mailing list |