SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL commands via the eid parameter, when accessed through the "Preview message" functionality.
| Software | From | Fixed in |
|---|---|---|
| invision_power_services / invision_community_blog | 1.2.4 | 1.2.4.x |