Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that bypass AWBSs anti-XSS input validation.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Advanced_webhost_billing_system | Advanced_webhost_billing_system | * | 2.5.1 (including) |