6.4
CVSSv2

CVE-2005-4702

Published: 31/12/2005 Updated: 05/09/2008
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

SQL injection vulnerability in the favorites module in index.php in IPBProArcade 2.5.2 allows remote malicious users to inject arbitrary SQL commands via the gameid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. In addition, the demonstration code as used by third parties suggests that this might be a different type of vulnerability related to shell metacharacters. Finally, this could be a rediscovery of CVE-2004-1430.

Vulnerable Product Search on Vulmon Subscribe to Product

ipbproarcade ipbproarcade 2.5.2

Exploits

source: wwwsecurityfocuscom/bid/15205/info A remote SQL injection vulnerability reportedly affects ipbProArcade The problem affects the 'gameid' parameter An attacker may leverage this issue to manipulate SQL query strings and potentially carry out arbitrary database queries This may facilitate the disclosure or corruption of sensiti ...