SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php.
| Software | From | Fixed in |
|---|---|---|
| xmb_forum / xmb | 1.9_beta | 1.9_beta.x |
| xmb_forum / xmb | 1.8_sp3 | 1.8_sp3.x |