Vulnerability CVE-2005-3871


Published: 2005-11-29   Modified: 2012-02-12

Description:
Multiple SQL injection vulnerabilities in Joels Bulletin board (JBB) 0.9.9rc3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nr parameter in topiczeigen.php, (2) forum and (3) zeigeseite parameters in showforum.php, (4) forum parameter in newtopic.php, and (5) tidnr parameter in neuerbeitrag.php.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
JBB -> JBB 

 References:
http://www.vupen.com/english/advisories/2005/2620
http://www.securityfocus.com/bid/15590
http://secunia.com/advisories/17727
http://www.osvdb.org/21151
http://www.osvdb.org/21150
http://www.osvdb.org/21149
http://www.osvdb.org/21148
http://pridels0.blogspot.com/2005/11/jbb-sql-inj-vuln.html

Copyright 2024, cxsecurity.com

 

Back to Top