Multiple SQL injection vulnerabilities in addentry.php in WoltLab Burning Book 1.1.2 allow remote attackers to execute arbitrary SQL commands via (1) the n parameter and (2) the User-Agent HTTP header.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Burning_book | Woltlab | 1.1.2 (including) | 1.1.2 (including) |