SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mercuryboard | Mercuryboard | 1.1.1 (including) | 1.1.1 (including) |