SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL commands via the eid parameter, when accessed through the Preview message functionality.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Invision_community_blog | Invision_power_services | 1.2.4 (including) | 1.2.4 (including) |