SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the Attached After field (GPC[search][datelineafter] variable), a related issue to CVE-2007-1573.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vbulletin | Jelsoft | * | 3.6.5 (including) |