CVE-2005-3816 Information

Description

Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode.

Reference

http://pridels0.blogspot.com/2005/11/freeforum-1x-cat-and-thread-sql-inj.html http://secunia.com/advisories/17720 http://securitytracker.com/id?1015269 http://www.osvdb.org/21086 http://www.securityfocus.com/bid/15559 http://www.vupen.com/english/advisories/2005/2571

Share on: