7.5
CVSSv2

CVE-2004-1966

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 770
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) FID parameter in board.php, (2) sortorder, perpage, or id parameters in member.php, (3) forums parameter in search.php, or (4) PID or FID parameters in post.php.

Vulnerable Product Search on Vulmon Subscribe to Product

openbb openbb 1.0.0 rc2

openbb openbb 1.0.8

openbb openbb 1.0.6

openbb openbb 1.0.0 beta1

openbb openbb 1.0.5

openbb openbb 1.0.0 rc3

openbb openbb 1.0.0 rc1

Exploits

source: wwwsecurityfocuscom/bid/10214/info It has been reported that OpenBB is affected by multiple input validation vulnerabilities These issues are due to a failure of the application to properly sanitize user supplied user input The SQL issues may allow a remote attacker to manipulate query logic, potentially leading to un ...
source: wwwsecurityfocuscom/bid/10214/info It has been reported that OpenBB is affected by multiple input validation vulnerabilities These issues are due to a failure of the application to properly sanitize user supplied user input The SQL issues may allow a remote attacker to manipulate query logic, potentially leading to ...
source: wwwsecurityfocuscom/bid/10214/info It has been reported that OpenBB is affected by multiple input validation vulnerabilities These issues are due to a failure of the application to properly sanitize user supplied user input The SQL issues may allow a remote attacker to manipulate query logic, potentially leading to ...
source: wwwsecurityfocuscom/bid/10214/info It has been reported that OpenBB is affected by multiple input validation vulnerabilities These issues are due to a failure of the application to properly sanitize user supplied user input The SQL issues may allow a remote attacker to manipulate query logic, potentially leading to unau ...