Vulnerabilities > CVE-2005-1554 - SQL Injection vulnerability in Wowbb web Forum 1.6/1.61/1.62
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
SQL injection vulnerability in view_user.php in WowBB 1.6, 1.61, and 1.62 allows remote attackers to execute arbitrary SQL commands via the sort_by parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | CGI abuses |
NASL id | WOWBB_SQL_INJECTION.NASL |
description | The remote host is running WowBB, a web-based forum written in PHP. The remote version of this software is vulnerable to SQL injection attacks through the script |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18221 |
published | 2005-05-11 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18221 |
title | WowBB view_user.php Multiple Parameter SQL Injection |