Vulnerabilities > CVE-2005-3918 - Unspecified vulnerability in Ovbb

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
ovbb
exploit available

Summary

Multiple SQL injection vulnerabilities in OvBB 0.08a allow remote attackers to execute arbitrary SQL commands via the (1) threadid parameter to thread.php and (2) userid parameter to profile.php. NOTE: the vendor disputes these issues, saying "these reports are completely unsubstantial.

Exploit-Db

  • descriptionOvBB 0.x thread.php threadid Parameter SQL Injection. CVE-2005-3918. Webapps exploit for php platform
    idEDB-ID:26589
    last seen2016-02-03
    modified2005-11-24
    published2005-11-24
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/26589/
    titleOvBB 0.x thread.php threadid Parameter SQL Injection
  • descriptionOvBB 0.x profile.php userid Parameter SQL Injection. CVE-2005-3918. Webapps exploit for php platform
    idEDB-ID:26590
    last seen2016-02-03
    modified2005-11-24
    published2005-11-24
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/26590/
    titleOvBB 0.x profile.php userid Parameter SQL Injection