7.5
CVSSv2

CVE-2005-3259

Published: 20/10/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote malicious users to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) "search this thread" feature, (3) "search for posts" feature, (4) "forgot password" feature, (5) list parameter in userlistpre.php, and the (6) select, (7) categ, and (8) to parameters in index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

versatilebulletinboard versatilebulletinboard 1.0.0.rc2

Exploits

<?php # --- versatile_xplphp 408 11/10/2005 # # # # versatileBulletinBoard 100 RC2 ( possibly prior versions) SQL injection / # # board takeover # # ...