Lucene search

K
cveMitreCVE-2005-1642
HistoryMay 17, 2005 - 4:00 a.m.

CVE-2005-1642

2005-05-1704:00:00
mitre
web.nvd.nist.gov
35
sql injection
woltlab burning board
remote attackers
arbitrary commands

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.4

Confidence

Low

EPSS

0.021

Percentile

89.1%

SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.

Affected configurations

Nvd
Node
woltlabburning_boardMatch2.0
VendorProductVersionCPE
woltlabburning_board2.0cpe:2.3:a:woltlab:burning_board:2.0:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.4

Confidence

Low

EPSS

0.021

Percentile

89.1%