CVE-2008-6970 Information

Description

SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.

Reference

http://osvdb.org/47954 http://secunia.com/advisories/31804 http://www.gulftech.org/?node=research&article_id=00130-09082008 http://www.securityfocus.com/bid/31074 http://www.ubbcentral.com/forums/ubbthreads.php/topics/216722/ https://exchange.xforce.ibmcloud.com/vulnerabilities/44976

Share on: