Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-3254

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2006-3254
Last Modified 05 Sep 2008 05:06:38
Published 27 Jun 2006 09:45:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-3254

Summary

SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

Vulnerable Systems

Application

  • Woltlab Burning Board 2.0 Rc2


References

BID - 18597

BUGTRAQ - 20060622 WBB<<---v2.0 RC2 "newthread.php" SQL Injection

XF - wbb-newthread-sql-injection(27350)

SECTRACK - 1016374

SREASON - 1154


Last Updated: 27 May 2016 10:42:56