Vulnerabilities > CVE-2004-1519

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
exploit available

Summary

SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.

Vulnerable Configurations

Part Description Count
Application
Benjamin_Curtis
1

Exploit-Db

descriptionphpBugTracker 1.6.0 - Multiple Vulnerabilities. CVE-2004-1519,CVE-2015-2142,CVE-2015-2143,CVE-2015-2145,CVE-2015-2147. Webapps exploit for php platform
idEDB-ID:36160
last seen2016-02-04
modified2015-02-23
published2015-02-23
reporterSteffen Rösemann
sourcehttps://www.exploit-db.com/download/36160/
titlephpBugTracker 1.6.0 - Multiple Vulnerabilities

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/130463/SROEADV-2015-16.txt
idPACKETSTORM:130463
last seen2016-12-05
published2015-02-19
reporterSteffen Roesemann
sourcehttps://packetstormsecurity.com/files/130463/phpBugTracker-1.6.0-CSRF-XSS-SQL-Injection.html
titlephpBugTracker 1.6.0 CSRF / XSS / SQL Injection