"value":"Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php. NOTE: the auction_rating.php vector is already covered by CVE-2005-1234. NOTE: the original disclosure states that the product name is \"PHP-Auction\", but this is probably an error."
},
{
"lang":"es",
"value":"M\u00faltiples vulnerabilidades de inyecci\u00f3n SQL en phpbb-Auction permiten a atacantes remotos ejecutar comandos SQL de su elecci\u00f3n a trav\u00e9s del par\u00e1metro (1) \"ar\" en auction_room.php y (2) \"u\" en auction_store.php. \r\nNOTA: El vector auction_rating.php est\u00e1 ya descrito en CVE-2005-1234.\r\nNOTA: La descripci\u00f3n original apunta que el nombre de producto es \"PHP-Auction\", pero es un error probablemente."