Vulnerabilities > CVE-2004-1555 - SQL Injection vulnerability in BroadBoard Message Board
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywords parameter to search.asp, (2) handle parameter to profile.asp, (3) txtUserHandle parameter to reg2.asp or (4) txtUserEmail parameter to forgot.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description FreezingCold Broadboard search.asp SQL Injection. CVE-2004-1555. Webapps exploit for asp platform id EDB-ID:24625 last seen 2016-02-02 modified 2004-09-27 published 2004-09-27 reporter pigrelax source https://www.exploit-db.com/download/24625/ title FreezingCold Broadboard search.asp SQL Injection description FreezingCold Broadboard profile.asp SQL Injection. CVE-2004-1555. Webapps exploit for asp platform id EDB-ID:24626 last seen 2016-02-02 modified 2004-09-27 published 2004-09-27 reporter pigrelax source https://www.exploit-db.com/download/24626/ title FreezingCold Broadboard profile.asp SQL Injection
Nessus
NASL family | CGI abuses |
NASL id | BROADBOARD_SQL_INJECTION.NASL |
description | The remote host appears to be running BroadBoard, an ASP script designed to manage a web-based bulletin-board system. There is a flaw in the remote software that could allow a remote attacker to inject arbitrary SQL commands, which could in turn be used to gain administrative access on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14828 |
published | 2004-09-27 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14828 |
title | BroadBoard Multiple Script SQL Injection |
code |
|
References
- http://marc.info/?l=bugtraq&m=109630777608244&w=2
- http://secunia.com/advisories/12658
- http://securitytracker.com/id?1011419
- http://www.securityfocus.com/bid/11250
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17498
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17500
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17501
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17502