SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to execute arbitrary SQL commands via the Query parameter in a search action to forum.php, a different vector than CVE-2005-3686.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T05:27:54.889Z
Reserved: 2009-06-05T00:00:00
Link: CVE-2009-1947

No data.

Status : Modified
Published: 2009-06-05T21:30:00.280
Modified: 2024-11-21T01:03:45.670
Link: CVE-2009-1947

No data.