Vulnerabilities > CVE-2005-4139 - Input Validation vulnerability in Thwboard Beta 2.8

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
thwboard
exploit available

Summary

Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user parameter array in v_profile.php, and (3) the userid parameter in misc.php.

Vulnerable Configurations

Part Description Count
Application
Thwboard
1

Exploit-Db

  • descriptionThwboard Beta 2.8 misc.php userid Parameter SQL Injection. CVE-2005-4139 . Webapps exploit for php platform
    idEDB-ID:26757
    last seen2016-02-03
    modified2005-12-07
    published2005-12-07
    reportertrueend5
    sourcehttps://www.exploit-db.com/download/26757/
    titleThwboard Beta 2.8 misc.php userid Parameter SQL Injection
  • descriptionThwboard Beta 2.8 v_profile.php user Parameter SQL Injection. CVE-2005-4139. Webapps exploit for php platform
    idEDB-ID:26756
    last seen2016-02-03
    modified2005-12-07
    published2005-12-07
    reportertrueend5
    sourcehttps://www.exploit-db.com/download/26756/
    titleThwboard Beta 2.8 v_profile.php user Parameter SQL Injection
  • descriptionThwboard Beta 2.8 calendar.php year Parameter SQL Injection. CVE-2005-4139. Webapps exploit for php platform
    idEDB-ID:26755
    last seen2016-02-03
    modified2005-12-07
    published2005-12-07
    reportertrueend5
    sourcehttps://www.exploit-db.com/download/26755/
    titleThwboard Beta 2.8 calendar.php year Parameter SQL Injection