SQL injection vulnerability in upgradev1.php in X7 Chat 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the old_prefix parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| X7_chat | X7_group | 2.0 (including) | 2.0 (including) |
| X7_chat | X7_group | 2.0.2 (including) | 2.0.2 (including) |
| X7_chat | X7_group | 2.0.4 (including) | 2.0.4 (including) |