SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/426583 | mailing list exploit |
http://www.osvdb.org/23810 | vdb entry |
http://www.securityfocus.com/bid/16914 | vdb entry |
http://www.osvdb.org/23808 | vdb entry |
http://www.nukedx.com/?viewdoc=17 |