Multiple SQL injection vulnerabilities in Simple PHP Forum before 0.4 allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) logon_user.php and (2) update_profile.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Simple_php_forum | Simple_php_forum | 0.1 (including) | 0.1 (including) |
Simple_php_forum | Simple_php_forum | 0.2 (including) | 0.2 (including) |
Simple_php_forum | Simple_php_forum | 0.3 (including) | 0.3 (including) |