Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2005-2058 | First vendor Publication | 2005-06-29 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2058 |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
17533 | UBB.threads Rating System Main Parameter SQL Injection UBB.threads contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'Rating System' not properly sanitizing user-supplied input to the 'Main' parameter. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database. |
17532 | UBB.threads grabnext.php posted Parameter SQL Injection UBB.threads contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'grabnext.php' script not properly sanitizing user-supplied input to the 'posted' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database. |
17531 | UBB.threads notifymod.php Number Parameter SQL Injection UBB.threads contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'notifymod.php' script not properly sanitizing user-supplied input to the 'Number' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database. |
17530 | UBB.threads addfav.php main Parameter SQL Injection UBB.threads contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'addfav.php' script not properly sanitizing user-supplied input to the 'main' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database. |
17529 | UBB.threads viewmessage.php message Parameter SQL Injection UBB.threads contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'viewmessage.php' script not properly sanitizing user-supplied input to the 'message' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database. |
17528 | UBB.threads mailthread.php Number Parameter SQL Injection UBB.threads contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'mailthread.php' script not properly sanitizing user-supplied input to the 'Number' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database. |
17527 | UBB.threads modifypost.php Number Parameter SQL Injection UBB.threads contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'modifypost.php' script not properly sanitizing user-supplied input to the 'Number' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database. |
17526 | UBB.threads calendar.php Multiple Parameter SQL Injection UBB.threads contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'calendar.php' script not properly sanitizing user-supplied input to the 'year' or 'month' variables. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database. |
17525 | UBB.threads download.php Number Parameter SQL Injection UBB.threads contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'download.php' script not properly sanitizing user-supplied input to the 'Number' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2005-04-20 | Name : The remote web server contains a PHP application that is affected by numerous... File : ubbthreads_printthread_sql_injection.nasl - Type : ACT_MIXED_ATTACK |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:22:04 |
|
2024-11-28 12:07:12 |
|
2021-05-04 12:03:02 |
|
2021-04-22 01:03:18 |
|
2020-05-23 00:16:39 |
|
2016-10-18 12:01:43 |
|
2014-02-17 10:31:54 |
|
2013-05-11 11:27:48 |
|