Vulnerabilities > CVE-2005-2323 - SQL-Injection vulnerability in Class-1 Forum

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
class-1
clever-copy
exploit available

Summary

Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id parameter to viewattach.php, (2) viewuser_id parameter to users.php, or the (3) id or (4) forum parameter to viewforum.php.

Vulnerable Configurations

Part Description Count
Application
Class-1
2
Application
Clever_Copy
1

Exploit-Db

descriptionphpMyFamily <= 1.4.0 SQL Injection Exploit. CVE-2005-2323. Webapps exploit for php platform
idEDB-ID:1208
last seen2016-01-31
modified2005-03-27
published2005-03-27
reporterbasher13
sourcehttps://www.exploit-db.com/download/1208/
titlephpMyFamily <= 1.4.0 - SQL Injection Exploit