SQL injection vulnerability in message.php in VBZooM 1.11 and earlier allows remote attackers to execute arbitrary SQL commands via the UserID parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Vbzoom | Vbzoom | 1.00 (including) | 1.00 (including) |
| Vbzoom | Vbzoom | 1.01 (including) | 1.01 (including) |
| Vbzoom | Vbzoom | 1.11 (including) | 1.11 (including) |