bb_func_unsub.php in MiniBB 3.1 prior to 20141127 uses an incorrect regular expression, which allows remote malicious users to conduct SQl injection attacks via the code parameter in an unsubscribe action to index.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
minibb minibb |