CVE

Id
93015  
CVE No.
CVE-2016-6195  
Status
Candidate  
Description
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wild in July 2016.  
Phase
Assigned (20160711)  
Votes
None (candidate not yet proposed)  
Comments