Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Calimba | Roberto_butti | 0.99.1 (including) | 0.99.1 (including) |
Calimba | Roberto_butti | 0.99.2_beta (including) | 0.99.2_beta (including) |