SQL injection vulnerability in message.php in VBZooM 1.11 and earlier allows remote attackers to execute arbitrary SQL commands via the UserID parameter.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/27295 | vdb entry |
http://www.securityfocus.com/archive/1/437655 | mailing list exploit |
http://www.securityfocus.com/bid/18497 | vdb entry |
http://securityreason.com/securityalert/1148 | third party advisory |