members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName, (3) FirstName, (4) LastName, or (5) INITIAL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Snitz_forums_2000 | Snitz_communications | 3.0 (including) | 3.0 (including) |
Snitz_forums_2000 | Snitz_communications | 3.1-sr4 (including) | 3.1-sr4 (including) |
Snitz_forums_2000 | Snitz_communications | 3.3 (including) | 3.3 (including) |
Snitz_forums_2000 | Snitz_communications | 3.3.01 (including) | 3.3.01 (including) |
Snitz_forums_2000 | Snitz_communications | 3.3.02 (including) | 3.3.02 (including) |
Snitz_forums_2000 | Snitz_communications | 3.3.03 (including) | 3.3.03 (including) |