SQL vulnerabilità iniettabile in index.php in miniBB 1.7f e precedenti permette attaccanti remoti di eseguire comandi SQL arbitrari tramite il parametro utente in un’azione userinfo. |
http://www.securityfocus.com/bid/11688 http://www.minibb.net/forums/index.php?action=vthread&forum=9&topic=1854 http://www.minibb.net/forums/index.php?action=vthread&forum=1&topic=1767 http://www.osvdb.org/11711 http://securitytracker.com/id?1012164 https://exchange.xforce.ibmcloud.com/vulnerabilities/18080 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2456 |
Vulnerabilità: CVE-2004-2456
