Vulnerabilities > CVE-2004-2350 - SQL Injection vulnerability in PHPBB Search.PHP Search_Results Parameter

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
phpbb-group
exploit available

Summary

SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL and gain privileges via the search_results parameter.

Exploit-Db

descriptionPHPBB 1.x/2.0.x Search.PHP Search_Results Parameter SQL Injection Vulnerability. CVE-2004-2350. Webapps exploit for php platform
idEDB-ID:23821
last seen2016-02-02
modified2004-01-04
published2004-01-04
reporterpokleyzz
sourcehttps://www.exploit-db.com/download/23821/
titlePHPBB 1.x/2.0.x Search.PHP Search_Results Parameter SQL Injection Vulnerability