Lucene search

K
cveMitreCVE-2004-0323
HistoryDec 31, 2004 - 5:00 a.m.

CVE-2004-0323

2004-12-3105:00:00
mitre
web.nvd.nist.gov
26
xmb
sql injection
vulnerability
remote
privileges
cve-2004-0323

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.4

Confidence

Low

EPSS

0.007

Percentile

80.6%

Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta.

Affected configurations

Nvd
Node
xmb_forumxmbMatch1.8
OR
xmb_forumxmbMatch1.8_sp1
OR
xmb_forumxmbMatch1.8_sp2
VendorProductVersionCPE
xmb_forumxmb1.8cpe:2.3:a:xmb_forum:xmb:1.8:*:*:*:*:*:*:*
xmb_forumxmb1.8_sp1cpe:2.3:a:xmb_forum:xmb:1.8_sp1:*:*:*:*:*:*:*
xmb_forumxmb1.8_sp2cpe:2.3:a:xmb_forum:xmb:1.8_sp2:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.4

Confidence

Low

EPSS

0.007

Percentile

80.6%

Related for CVE-2004-0323