CVE-2008-6777 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a confirm action the (2) user parameter in a newconfirm action and (3) reqpwd action to member.php; and the (4) quote parameter in a post action and (5) pid parameter in an edit action to post.php different vectors than CVE-2005-0413.2 and CVE-2007-6667.
Reference
http://secunia.com/advisories/28280 http://www.securityfocus.com/bid/31995 https://exchange.xforce.ibmcloud.com/vulnerabilities/46238 https://www.exploit-db.com/exploits/6879
Share on: