Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to auction_rating.php or (2) ar parameter to action_offer.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpbb-auction | Phpbb_group | 1.0m (including) | 1.0m (including) |
Phpbb-auction | Phpbb_group | 1.2m (including) | 1.2m (including) |