SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpgb | Phpgb | 1.10 (including) | 1.10 (including) |
Phpgb | Phpgb | 1.20 (including) | 1.20 (including) |
Phpgb | Phpgb | 1.30 (including) | 1.30 (including) |