7.5
CVE-2005-3871
- EPSS 1.41%
- Veröffentlicht 29.11.2005 11:03:00
- Zuletzt bearbeitet 16.06.2026 22:17:47
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple SQL injection vulnerabilities in Joels Bulletin board (JBB) 0.9.9rc3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nr parameter in topiczeigen.php, (2) forum and (3) zeigeseite parameters in showforum.php, (4) forum parameter in newtopic.php, and (5) tidnr parameter in neuerbeitrag.php.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.41% | 0.691 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://pridels0.blogspot.com/2005/11/jbb-sql-inj-vuln.html
http://secunia.com/advisories/17727
http://www.osvdb.org/21148
http://www.osvdb.org/21149
http://www.osvdb.org/21150
http://www.osvdb.org/21151
http://www.securityfocus.com/bid/15590
http://www.vupen.com/english/advisories/2005/2620