Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start parameter in a search action or (2) type parameter in a top action.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Musicbox | Musicbox | * | 2.3.3 (including) |