First published: Mon Jul 31 2006(Updated: )
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php. NOTE: the auction_rating.php vector is already covered by CVE-2005-1234. NOTE: the original disclosure states that the product name is "PHP-Auction", but this is probably an error.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpbb Group Phpbb-auction | =1.2m | |
Phpbb Group Phpbb-auction | =1.3m | |
Phpbb Group Phpbb-auction | =1.0m |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.