SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']).
| Software | From | Fixed in |
|---|---|---|
| mercuryboard / mercuryboard | 1.1 | 1.1.x |
| mercuryboard / mercuryboard | - | 1.1.5.x |
| mercuryboard / mercuryboard | 1.1.1 | 1.1.1.x |
| mercuryboard / mercuryboard | 1.0 | 1.0.x |
| mercuryboard / mercuryboard | 1.1.2 | 1.1.2.x |