7.5
CVSSv2

CVE-2004-1515

Published: 31/12/2004 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote malicious users to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.

Vulnerable Product Search on Vulmon Subscribe to Product

jelsoft vbulletin 3.0.0

jelsoft vbulletin 3.0.4

jelsoft vbulletin 3.0.5

jelsoft vbulletin 3.0.0_beta_2

jelsoft vbulletin 3.0.0_can4

jelsoft vbulletin 3.0.6

jelsoft vbulletin 3.0_beta_2

jelsoft vbulletin 3.0.0_rc4

jelsoft vbulletin 3.0.1

jelsoft vbulletin 3.0.2

jelsoft vbulletin 3.0.3

Exploits

Example: wwwexamplecom/lastphp?fsel=,userpassword%20as%20title,user%20%20%20%20username%20as%20lastposter%20FROM%20user,thread%20%20%20%20%20WHERE%20usergroupid=6%20LIMIT%201 # milw0rmcom [2004-11-15] ...