Description
Multiple SQL injection vulnerabilities in AstroDog Press Some Chess 1.5-RC2 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly including the gameID parameter in board.php.
Affected products
- astrodog_press / some_chess1.5_rc1 – 1.5_rc1
- astrodog_press / some_chess1.5_rc2 – 1.5_rc2
References
- MISChttp://sourceforge.net/forum/forum.php?forum_id=586734
- VENDOR_ADVISORYhttp://secunia.com/advisories/20885
- MISChttp://www.osvdb.org/26784
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/27489
- MISChttp://www.securityfocus.com/bid/18745
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2006/2609