Vulnerabilities > CVE-2005-1234 - SQL Injection vulnerability in PHPbb Group PHPbb-Auction 1.0M/1.2M

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
phpbb-group

Summary

Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to auction_rating.php or (2) ar parameter to action_offer.php.

Vulnerable Configurations

Part Description Count
Application
Phpbb_Group
2