CVE-2008-6091 Information

Description

SQL injection vulnerability in plugins.php in BMForum 5.6 when magic_quotes_gpc is disabled allows remote attackers to execute arbitrary SQL commands via the tagname parameter.

Reference

http://www.securityfocus.com/bid/31522 https://exchange.xforce.ibmcloud.com/vulnerabilities/45611 https://www.exploit-db.com/exploits/6642

Share on: