An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious SQL payloads via the "word" POST parameter in the words.php admin panel.
| Software | From | Fixed in |
|---|---|---|
| phpversion / vx_guestbook | 1.07 | 1.07.x |