SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to priv.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Open_tibia_server_cms | Open_tibia_server_cms | 2.0 (including) | 2.0 (including) |
Open_tibia_server_cms | Open_tibia_server_cms | 2.1.3 (including) | 2.1.3 (including) |
Open_tibia_server_cms | Open_tibia_server_cms | 2.1.4 (including) | 2.1.4 (including) |
Open_tibia_server_cms | Open_tibia_server_cms | 2.1.5 (including) | 2.1.5 (including) |