CVE-2008-6091
09.02.2009, 17:30
SQL injection vulnerability in plugins.php in BMForum 5.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tagname parameter.
Vendor | Product | Version |
---|---|---|
bmforum | bmforum | 5.6 |
𝑥
= Vulnerable software versions