Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) hideemail, (2) languagex, (3) xthetimeoffset, and (4) xthetimeformat parameters during account registration.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/438597/100/0/threaded | mailing list |
http://www.osvdb.org/26457 | vdb entry |
http://secunia.com/advisories/20152 | third party advisory vendor advisory |
http://securitytracker.com/id?1016309 | vdb entry |
http://secunia.com/secunia_research/2006-44/advisory | vendor advisory |
http://www.vupen.com/english/advisories/2006/2347 | vdb entry |
http://www.securityfocus.com/bid/18453 | vdb entry |
http://www.securityfocus.com/archive/1/437228/100/100/threaded | mailing list |
http://securityreason.com/securityalert/1134 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27091 | vdb entry |