Multiple SQL injection vulnerabilities in Subdreamer 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the loginusername parameter or (2) cookies to (a) subdreamer.php, (b) ipb2.php, (c) phpbb2.php, (d) vbulletin2.php, and (e) vbulletin3.php.
Link | Tags |
---|---|
http://rst.void.ru/papers/advisory35.txt | vendor advisory |
http://www.osvdb.org/20379 | vdb entry |
http://www.osvdb.org/20380 | vdb entry |
http://www.osvdb.org/20382 | vdb entry |
http://www.osvdb.org/20378 | vdb entry |
http://www.osvdb.org/20381 | vdb entry |
http://secunia.com/advisories/17378 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/15238 | vdb entry exploit |
http://www.osvdb.org/20384 | vdb entry |