Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:17695
HistoryAug 05, 2007 - 12:00 a.m.

Aceboard forum, SQL injection

2007-08-0500:00:00
vulners.com
30

Aceboard is prone to a sql injection vulnerability because it fails to properly sanitize user-supplied input into Recherche.php form.

An attacker can exploit this issue to modify initial query and reveal information from mysql databse.

see u, karmaguedon