Vulnerabilities > CVE-2005-4259 - SQL Injection vulnerability in Aspbb 0.4

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
aspbb
exploit available

Summary

Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.

Vulnerable Configurations

Part Description Count
Application
Aspbb
1

Exploit-Db

  • descriptionASPBB 0.4 topic.asp TID Parameter SQL Injection. CVE-2005-4259. Webapps exploit for asp platform
    idEDB-ID:26821
    last seen2016-02-03
    modified2005-12-14
    published2005-12-14
    reporterDj_Eyes
    sourcehttps://www.exploit-db.com/download/26821/
    titleASPBB 0.4 topic.asp TID Parameter SQL Injection
  • descriptionASPBB 0.4 profile.asp PROFILE_ID Parameter SQL Injection. CVE-2005-4259. Webapps exploit for asp platform
    idEDB-ID:26823
    last seen2016-02-03
    modified2005-12-14
    published2005-12-14
    reporterDj_Eyes
    sourcehttps://www.exploit-db.com/download/26823/
    titleASPBB 0.4 profile.asp PROFILE_ID Parameter SQL Injection
  • descriptionASPBB 0.4 forum.asp FORUM_ID Parameter SQL Injection. CVE-2005-4259. Webapps exploit for asp platform
    idEDB-ID:26822
    last seen2016-02-03
    modified2005-12-14
    published2005-12-14
    reporterDj_Eyes
    sourcehttps://www.exploit-db.com/download/26822/
    titleASPBB 0.4 forum.asp FORUM_ID Parameter SQL Injection