Multiple SQL injection vulnerabilities in addentry.php in WoltLab Burning Book 1.1.2 allow remote attackers to execute arbitrary SQL commands via (1) the n parameter and (2) the User-Agent HTTP header.
Link | Tags |
---|---|
http://securityreason.com/securityalert/1774 | third party advisory |
http://www.vupen.com/english/advisories/2006/4062 | vdb entry |
http://www.securityfocus.com/archive/1/448796/100/100/threaded | mailing list |
http://www.security.nnov.ru/Odocument711.html | |
http://secunia.com/advisories/22442 | third party advisory |