Vulnerability CVE-2007-1902


Published: 2007-05-14   Modified: 2012-02-12

Description:
Multiple SQL injection vulnerabilities in SonicBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) part and (2) by parameters to (a) search.php, or the (2) id parameter to (b) viewforum.php.

Type:

CWE-Other

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Sonicbb -> Sonicbb 

 References:
http://marc.info/?l=full-disclosure&m=117914598917534&w=2
http://www.netvigilance.com/advisory0019
http://www.securityfocus.com/archive/1/468536/100/0/threaded
http://www.securityfocus.com/bid/23964
http://www.vupen.com/english/advisories/2007/1816
https://exchange.xforce.ibmcloud.com/vulnerabilities/34258

Copyright 2024, cxsecurity.com

 

Back to Top