7.5
CVSSv2

CVE-2005-3816

Published: 26/11/2005 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and previous versions and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode.

Vulnerable Product Search on Vulmon Subscribe to Product

zoneo-soft freeforum

Exploits

source: wwwsecurityfocuscom/bid/15559/info freeForum is prone to multiple SQL injection vulnerabilities These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks Successful exploitation could result in a compromise of the application, disc ...