Description
|
|
Several vulnerabilities were reported in Chipmunk Forums, which can be exploited by an attacker to execute arbitrary SQL commands. These vulnerabilities exist due to a missing input sanitising error when handling the "email" (getpassword.php), "user" (authenticate.php), "ID" (edit.php), "searchterm" (search.php), "name", "title" and "post" (newtopic.php) variables, which could be exploited to compromise a vulnerable system using specially crafted SQL commands.
|