FreezingCold Broadboard - 'profile.asp' SQL Injection

Related Vulnerabilities: CVE-2004-1555  
Publish Date: 27 Sep 2004
Author: pigrelax
                source: http://www.securityfocus.com/bid/11250/info
 
Reportedly BroadBoard Message Board is affected by multiple SQL injection vulnerabilities. These issues are due to a failure of the application to properly sanitize user supplied URI input prior to using it in an SQL query.
 
An attacker may exploit these issues to manipulate SQL queries, potentially revealing or corrupting sensitive database data. These issues may also facilitate attacks against the underlying database software.

http://broadboard/forum/profile.asp?handle=['SQL code]