CVE-2007-1902 Information

Description

Multiple SQL injection vulnerabilities in SonicBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) part and (2) by parameters to (a) search.php or the (2) id parameter to (b) viewforum.php.

Reference

http://marc.info/?l=full-disclosure&m=117914598917534&w=2 http://secunia.com/advisories/25279 http://www.netvigilance.com/advisory0019 http://www.osvdb.org/33907 http://www.securityfocus.com/archive/1/468536/100/0/threaded http://www.securityfocus.com/bid/23964 http://www.vupen.com/english/advisories/2007/1816 https://exchange.xforce.ibmcloud.com/vulnerabilities/34258

Share on: