HIGH
SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached After" field (GPC['search']['datelineafter'] variable), a related issue to CVE-2007-1573
Published May 30, 2007
8.5
HIGHCVSS 2.0
EPSS 1.31%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.