CVE-2008-2023 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) invisible and (2) timeoffset parameters to profile/controlpanel.asp and the (3) attachmentid parameter to forums/attach-file.asp.
Reference
http://secunia.com/advisories/29979 http://www.bugreport.ir/?/37 http://www.securityfocus.com/bid/28961 https://exchange.xforce.ibmcloud.com/vulnerabilities/42044 https://www.exploit-db.com/exploits/5507
Share on: