Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via crafted POST requests that store PHP code in a database that is later processed by eval, as demonstrated using SQL injection via the n parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Burning_book | Woltlab | 1.1.2 (including) | 1.1.2 (including) |