SQL injection vulnerability in message.php in VBZooM 1.11 and earlier allows remote attackers to execute arbitrary SQL commands via the UserID parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vbzoom | Vbzoom | 1.00 (including) | 1.00 (including) |
Vbzoom | Vbzoom | 1.01 (including) | 1.01 (including) |
Vbzoom | Vbzoom | 1.11 (including) | 1.11 (including) |