SQL injection vulnerability in search.php in PunBB before 1.2.14, when the PHP installation is vulnerable to CVE-2006-3017, allows remote attackers to execute arbitrary SQL commands via the result_list array parameter, which is not initialized. Successful exploitation requires that "register_globals" is enabled.
This vulnerability is addressed in the following product release:
PunBB, PunBB, 1.2.14
Publication date: Tue, 07 Nov 2006 00:07:00 +0000