Multiple SQL injection vulnerabilities in OvBB 0.08a allow remote attackers to execute arbitrary SQL commands via the (1) threadid parameter to thread.php and (2) userid parameter to profile.php. NOTE: the vendor disputes these issues, saying these reports are completely unsubstantial.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ovbb | Ovbb | 0.1a (including) | 0.1a (including) |
Ovbb | Ovbb | 0.2a (including) | 0.2a (including) |
Ovbb | Ovbb | 0.3a (including) | 0.3a (including) |
Ovbb | Ovbb | 0.4a (including) | 0.4a (including) |
Ovbb | Ovbb | 0.5a (including) | 0.5a (including) |
Ovbb | Ovbb | 0.6a (including) | 0.6a (including) |
Ovbb | Ovbb | 0.7a (including) | 0.7a (including) |
Ovbb | Ovbb | 0.8a (including) | 0.8a (including) |