Security Advisory

CVE-2007-3526

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-07-03 18:00:00
Last updated 2024-08-07 14:21:35
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the news_id parameter to view_news.php, (2) the cat_id parameter to view_events.php, or (3) the member_id parameter to video_gallery.php.