Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PunBB Profile.PHP SQL Injection Vulnerability

PunBB is affected by a SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input through the 'profile.php' script before using it in a SQL query.

This issue can be successfully exploited to gain administrative access to a vulnerable forum.

PunBB 1.2.4 and prior versions are vulnerable.







 

Privacy Statement
Copyright 2008, SecurityFocus