Release DateMar 01, 2007 |
Severitymedium |
ImpactData Manipulation. |
DescriptionPhilboard has a SQL-injection vulnerability. A remote attacker could execute arbitrary SQL commands in the back-end database via a specially-crafted HTTP request to the "philboard_forum.asp" script with injected SQL statements in the "forumid" parameter. |
Affected ProductsPhilboard version 1.14 and prior. |
Recommended ActionsCurrently we are not aware of any vendor-supplied patches for this issue.http://www.nabocorp.com/nabopoll/ |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2007-0920 |
Reference/shttp://www.securityfocus.com/bid/22532 (BugTraq) |