SQL injection vulnerability in function/showprofile.php in FlexBB 0.5.5 allows remote attackers to execute arbitrary SQL commands, and view all usernames and passwords, via the id parameter to the showprofile page in index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Flexbb | Flexbb | 0.5.5 (including) | 0.5.5 (including) |