Multiple SQL injection vulnerabilities in APBoard 2.2-r3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) PHPSESSID parameter in board.php and (2) viewcatmod parameter in main.php.
| Software | From | Fixed in |
|---|---|---|
| apboard / apboard | - | 2.2_r3.x |