SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL commands via the by User field (aka the TXbyuser parameter).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Uniforum | Uniforum | * | 4 (including) |