SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary SQL commands via the msgid parameter.
| Software | From | Fixed in |
|---|---|---|
| papoo / papoo | 2.1.2 | 2.1.2.x |
| papoo / papoo | 3.0.0 | 3.0.0.x |
| papoo / papoo | 3.0.0_beta1 | 3.0.0_beta1.x |
| papoo / papoo | 2.1.4 | 2.1.4.x |
| papoo / papoo | 2.1.5 | 2.1.5.x |
| papoo / papoo | - | 3.0.0_rc3.x |