7.5
CVSSv2

CVE-2002-1505

Published: 02/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and previous versions allows remote malicious users to modify the database and possibly gain privileges via the boardid parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

woltlab burning board 2.0_beta_5

woltlab burning board 2.0_beta_3

woltlab burning board 2.0_beta_4

woltlab burning board

Exploits

source: wwwsecurityfocuscom/bid/5675/info WoltLab is prone to SQL injection attacks This is due to insufficient sanitization of parameters handled by the boardphp script, which may be supplied externally via the query string in a web request The logic of a SQL query made by the script may be modified, resulting in the potential for da ...