4.6
CVSSv2

CVE-2001-1472

Published: 03/08/2001 Updated: 11/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 1.4.0

phpbb group phpbb 1.4.1

Exploits

source: wwwsecurityfocuscom/bid/3142/info phpBB is free, open-source, easy-to-use web forums software An issue exists in phpBB which allows a remote attacker to manipulate SQL queries in such a way as to gain an administrative account with the service This problem is due to improper validation of user-supplied input by certain variabl ...