SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Burning_book | Woltlab | 1.0_gold (including) | 1.0_gold (including) |
Burning_book | Woltlab | 1.1.1e (including) | 1.1.1e (including) |