6.5
CVSSv2

CVE-2014-2339

Published: 19/03/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) subject or (2) content parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sir gnuboard 4.34.20

sir gnuboard

sir gnuboard 4.31.3

sir gnuboard 4.33.2

sir gnuboard 4.34.21

sir gnuboard 4.31.4

Exploits

source: wwwsecurityfocuscom/bid/66228/info GNUboard is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database wwwex ...