CVE

Id
14108  
CVE No.
CVE-2005-2902  
Status
Candidate  
Description
SQL injection vulnerability in class-1 Forum Software 0.24.4 allows remote attackers to execute arbitrary SQL commands and bypass the file extension check via SQL code in the file extension of an uploaded file.  
Phase
Assigned (20050914)  
Votes
None (candidate not yet proposed)  
Comments