Lucene search

K
cveMitreCVE-2008-4431
HistoryOct 03, 2008 - 10:22 p.m.

CVE-2008-4431

2008-10-0322:22:45
CWE-89
mitre
web.nvd.nist.gov
22
cve-2008-4431
sql injection
icebb
index.php
remote execution
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.4

Confidence

Low

EPSS

0.001

Percentile

50.7%

SQL injection vulnerability in index.php in IceBB 1.0-rc9.3 and earlier allows remote attackers to execute arbitrary SQL commands via the skin parameter, probably related to an incorrect protection mechanism in the clean_string function in includes/functions.php.

Affected configurations

Nvd
Node
icebbicebbRange1.0rc9.3
OR
icebbicebbMatch0.9rc1
OR
icebbicebbMatch0.9.1
OR
icebbicebbMatch0.9.2
OR
icebbicebbMatch0.9.2.1
OR
icebbicebbMatch0.9.3
OR
icebbicebbMatch0.9.3.1
OR
icebbicebbMatch1.0rc5
OR
icebbicebbMatch1.0rc5.1
OR
icebbicebbMatch1.0rc6
OR
icebbicebbMatch1.0rc7
OR
icebbicebbMatch1.0rc8
OR
icebbicebbMatch1.0rc9
OR
icebbicebbMatch1.0rc9.1
OR
icebbicebbMatch1.0rc9.2
VendorProductVersionCPE
icebbicebb*cpe:2.3:a:icebb:icebb:*:rc9.3:*:*:*:*:*:*
icebbicebb0.9cpe:2.3:a:icebb:icebb:0.9:rc1:*:*:*:*:*:*
icebbicebb0.9.1cpe:2.3:a:icebb:icebb:0.9.1:*:*:*:*:*:*:*
icebbicebb0.9.2cpe:2.3:a:icebb:icebb:0.9.2:*:*:*:*:*:*:*
icebbicebb0.9.2.1cpe:2.3:a:icebb:icebb:0.9.2.1:*:*:*:*:*:*:*
icebbicebb0.9.3cpe:2.3:a:icebb:icebb:0.9.3:*:*:*:*:*:*:*
icebbicebb0.9.3.1cpe:2.3:a:icebb:icebb:0.9.3.1:*:*:*:*:*:*:*
icebbicebb1.0cpe:2.3:a:icebb:icebb:1.0:rc5:*:*:*:*:*:*
icebbicebb1.0cpe:2.3:a:icebb:icebb:1.0:rc5.1:*:*:*:*:*:*
icebbicebb1.0cpe:2.3:a:icebb:icebb:1.0:rc6:*:*:*:*:*:*
Rows per page:
1-10 of 151

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.4

Confidence

Low

EPSS

0.001

Percentile

50.7%

Related for CVE-2008-4431