6.5
CVSSv2

CVE-2005-1051

Published: 02/05/2005 Updated: 18/10/2016
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.

Vulnerable Product Search on Vulmon Subscribe to Product

punbb punbb 1.0_alpha

punbb punbb 1.0_beta1

punbb punbb 1.1.2

punbb punbb 1.1.3

punbb punbb 1.1.4

punbb punbb 1.0_rc1

punbb punbb 1.0_rc2

punbb punbb 1.2.2

punbb punbb 1.2.3

punbb punbb 1.0

punbb punbb 1.0.1

punbb punbb 1.1

punbb punbb 1.1.1

punbb punbb 1.2.4

punbb punbb 1.0_beta2

punbb punbb 1.0_beta3

punbb punbb 1.1.5

punbb punbb 1.2.1

Exploits

#!/usr/bin/python ####################################################################### # _ _ _ _ ___ _ _ ___ # | || | __ _ _ _ __| | ___ _ _ ___ __| | ___ | _ \| || || _ \ # | __ |/ _` || '_|/ _` |/ -_)| ' \ / -_)/ _` ||___|| _/| __ || _/ # |_||_|\__,_||_| \__,_|\___||_||_|\___|\__,_| |_ ...