Multiple SQL injection vulnerabilities in Joker Board (aka JBoard) 2.0 and previous versions allow remote malicious users to execute arbitrary SQL commands via (1) core/select.php or (2) the city parameter to top_add.inc.php, reachable through sboard.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
allpublication jboard |