Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL commands via unknown parameters to the gbook module and unspecified other components.
| Software | From | Fixed in |
|---|---|---|
| clansphere / clansphere | 2009.0-rc3 | 2009.0-rc3.x |
| clansphere / clansphere | 2009.0-rc1 | 2009.0-rc1.x |
| clansphere / clansphere | 2007.4.3 | 2007.4.3.x |
| clansphere / clansphere | 2008.2 | 2008.2.x |
| clansphere / clansphere | 2009.0-rc2 | 2009.0-rc2.x |
| clansphere / clansphere | - | 2009.0.x |
| clansphere / clansphere | 2008.2.1 | 2008.2.1.x |
| clansphere / clansphere | 2008.1 | 2008.1.x |
| clansphere / clansphere | 2007.4 | 2007.4.x |
| clansphere / clansphere | 2007.4.4 | 2007.4.4.x |
| clansphere / clansphere | 2007.4.1 | 2007.4.1.x |
| clansphere / clansphere | 2007.4.2 | 2007.4.2.x |
| clansphere / clansphere | 2008 | 2008.x |