SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and previous versions allows remote malicious users to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']).
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mercuryboard mercuryboard 1.1.2 |
||
mercuryboard mercuryboard 1.1.1 |
||
mercuryboard mercuryboard 1.1 |
||
mercuryboard mercuryboard 1.0 |
||
mercuryboard mercuryboard |