Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feature in profile.php, (3) posts or (4) topics parameter to moderate.php.
References
Link | Resource |
---|---|
http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt | |
http://www.securityfocus.com/bid/12652 | Exploit Patch |
http://secunia.com/advisories/14394 | Patch Vendor Advisory |
http://secunia.com/advisories/14538 | Patch Vendor Advisory |
http://marc.info/?l=bugtraq&m=110927754230666&w=2 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/19473 |
Configurations
Information
Published : 2005-05-01 21:00
Updated : 2017-07-10 18:32
NVD link : CVE-2005-0569
Mitre link : CVE-2005-0569
JSON object : View
CWE
Products Affected
punbb
- punbb