CVE-2008-4431
03.10.2008, 22:22
SQL injection vulnerability in index.php in IceBB 1.0-rc9.3 and earlier allows remote attackers to execute arbitrary SQL commands via the skin parameter, probably related to an incorrect protection mechanism in the clean_string function in includes/functions.php.
Vendor | Product | Version |
---|---|---|
icebb | icebb | 𝑥 ≤ 1.0 |
icebb | icebb | 0.9:rc1 |
icebb | icebb | 0.9.1 |
icebb | icebb | 0.9.2 |
icebb | icebb | 0.9.2.1 |
icebb | icebb | 0.9.3 |
icebb | icebb | 0.9.3.1 |
icebb | icebb | 1.0:rc5 |
icebb | icebb | 1.0:rc5.1 |
icebb | icebb | 1.0:rc6 |
icebb | icebb | 1.0:rc7 |
icebb | icebb | 1.0:rc8 |
icebb | icebb | 1.0:rc9 |
icebb | icebb | 1.0:rc9.1 |
icebb | icebb | 1.0:rc9.2 |
𝑥
= Vulnerable software versions
References