[VIM] Blackboard (id) Remote SQL Injection

George A. Theall theall at tenablesecurity.com
Fri Feb 8 19:49:27 UTC 2008

Bugtraq 27696 was just added based on the following posting:


about a SQL injection vulnerability involving the 'forum_id' parameter  
of the 'philboard_forum.asp' script of something called Philboard.

To me, this seems to be the same issue as Bugtraq 22532 / milw0rm  
3295.  What am I missing???

