7.5

CVE-2005-2193

SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the array from being properly escaped.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PunbbPunbb Version1.0
PunbbPunbb Version1.0.1
PunbbPunbb Version1.0_alpha
PunbbPunbb Version1.0_beta1
PunbbPunbb Version1.0_beta2
PunbbPunbb Version1.0_beta3
PunbbPunbb Version1.0_rc1
PunbbPunbb Version1.0_rc2
PunbbPunbb Version1.1
PunbbPunbb Version1.1.1
PunbbPunbb Version1.1.2
PunbbPunbb Version1.1.3
PunbbPunbb Version1.1.4
PunbbPunbb Version1.1.5
PunbbPunbb Version1.2.1
PunbbPunbb Version1.2.2
PunbbPunbb Version1.2.3
PunbbPunbb Version1.2.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.626
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P