Vulnerabilities > CVE-2005-3259 - SQL Injection vulnerability in Versatilebulletinboard 1.0.0.Rc2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) "search this thread" feature, (3) "search for posts" feature, (4) "forgot password" feature, (5) list parameter in userlistpre.php, and the (6) select, (7) categ, and (8) to parameters in index.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | versatileBulletinBoard 1.00 RC2 (board takeover) SQL Injection Exploit. CVE-2005-3259. Webapps exploit for php platform |
id | EDB-ID:1245 |
last seen | 2016-01-31 |
modified | 2005-10-10 |
published | 2005-10-10 |
reporter | rgod |
source | https://www.exploit-db.com/download/1245/ |
title | versatileBulletinBoard 1.00 RC2 board takeover SQL Injection Exploit |
References
- http://marc.info/?l=bugtraq&m=112907535528616&w=2
- http://rgod.altervista.org/versatile100RC2.html
- http://secunia.com/advisories/17174/
- http://www.osvdb.org/19962
- http://www.osvdb.org/19963
- http://www.osvdb.org/19964
- http://www.osvdb.org/19965
- http://www.osvdb.org/19966
- http://www.osvdb.org/19967
- http://www.osvdb.org/19968
- http://www.securityfocus.com/bid/15068