Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-3394

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2005-3394
Last Modified 07 Mar 2011 09:26:28
Published 01 Nov 2005 07:47:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-3394

Summary

Multiple SQL injection vulnerabilities in forum.php in oaboard forum 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) channel parameter in the topics module and (2) topic parameter in the posting module.

Vulnerable Systems

Application

  • Oaboard 1.0


References

VUPEN - ADV-2005-2258

BID - 15245

BUGTRAQ - 20051030 SQL IN FORUM.PHP

SECUNIA - 17373

XF - oaboard-forum-script-sql-injection(22932)

OSVDB - 20420


Last Updated: 27 May 2016 10:40:55