Vulnerabilities > CVE-2003-1215 - Unspecified vulnerability in PHPbb Group PHPbb
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN phpbb-group
nessus
Summary
SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.
Vulnerable Configurations
Nessus
NASL family | CGI abuses |
NASL id | PHPBB_SQL_INJECTION2.NASL |
description | The remote host is running a version of phpBB older than 2.0.7. There is a flaw in the remote software that could allow anyone to inject arbitrary SQL commands, which may in turn be used to gain administrative access on the remote host or to obtain the MD5 hash of the password of any user. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11938 |
published | 2003-12-04 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11938 |
title | phpBB < 2.0.7 Multiple Script SQL Injection |
code |
|
References
- http://marc.info/?l=bugtraq&m=107273069130885&w=2
- http://marc.info/?l=bugtraq&m=107273069130885&w=2
- http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=161943
- http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=161943
- http://www.securityfocus.com/bid/9314
- http://www.securityfocus.com/bid/9314
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14096
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14096