7.5
CVSSv2

CVE-2005-3686

Published: 19/11/2005 Updated: 05/08/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in search.inc.php in Unclassified NewsBoard prior to 1.5.3 Patch 4 allows remote malicious users to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php.

Vulnerable Product Search on Vulmon Subscribe to Product

newsboard unclassified newsboard

Exploits

<?php # ---UNB153pl3_xplphp 1135 12/11/2005 # # # # Unclassified NewsBoard 153 patch level 3 "Datefrom" blind SQL # # injection / Admin MD5 password hash dump # # ...