PostNuke PNPHPBB2 Module Viewforum.PHP SQL Injection Vulnerability

The PostNuke PNphpBB2 module is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.

An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.

This issue affects PNphpBB2 1.2i and prior versions; other versions are also affected.


 

Privacy Statement
Copyright 2010, SecurityFocus