CVE-2007-5688 Information

Description

Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3 for phpBB and Invision Power Board (IPB or IP.Board) allow remote attackers to execute arbitrary SQL commands via the (1) go and (2) cat parameters.

Reference

http://secunia.com/advisories/27406 http://www.inj3ct-it.org/exploit/Multi_Host.txt http://www.securityfocus.com/archive/1/482838/100/0/threaded http://www.securityfocus.com/bid/26213 https://exchange.xforce.ibmcloud.com/vulnerabilities/37461

Share on: