CVE-2005-0661 Information

Description

SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) lastvisit cookie.

Reference

http://secunia.com/advisories/14450 http://securitytracker.com/id?1013351

Share on: