IceBB Avatar SQL Injection and PHP Code Execution - Secunia
IceBB Avatar SQL Injection and PHP Code Execution - Secunia
IceBB Avatar SQL Injection and PHP Code ExecutionSecunia, UK - Mar 27, 2007This can be exploited to execute arbitrary PHP code by uploading malicious PHP files. 2) The filename of uploaded avatars is not properly sanitised before …PBLang admin2.php PHP Code Execution Secuniaall 4 news articles