7.5

CVE-2005-3259

Exploit
Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) "search this thread" feature, (3) "search for posts" feature, (4) "forgot password" feature, (5) list parameter in userlistpre.php, and the (6) select, (7) categ, and (8) to parameters in index.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.57% 0.831
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=112907535528616&w=2
http://rgod.altervista.org/versatile100RC2.html
Vendor Advisory
Exploit
http://secunia.com/advisories/17174/
Vendor Advisory
http://www.osvdb.org/19962
http://www.osvdb.org/19963
http://www.osvdb.org/19964
http://www.osvdb.org/19965
http://www.osvdb.org/19966
http://www.osvdb.org/19967
http://www.osvdb.org/19968
http://www.securityfocus.com/bid/15068
Exploit