Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start parameter in a search action or (2) type parameter in a top action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Musicbox | Musicbox | * | 2.3.3 (including) |