CVE-2005-1585 Information

Description

Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php or (3) iCategory parameter in the query string to the forum directory.

Reference

http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html http://secunia.com/advisories/15200 http://www.osvdb.org/16326

Share on: