CVE-2009-3059 Information

Description

Multiple SQL injection vulnerabilities in Joker Board (aka JBoard) 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) core/select.php or (2) the city parameter to top_add.inc.php reachable through sboard.php.

Reference

http://packetstormsecurity.org/0908-exploits/jboard-sql.txt http://www.vupen.com/english/advisories/2009/2473

Share on: