VulnerabilityModified
CVE-2001-1472
SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.
MEDIUM 4.6EPSS 2.58%
Does this matter?
Lower severity and a low EPSS score (2.58%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.58% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- phpbb group/phpbb
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/314347US Government Resource
- http://www.securityfocus.com/archive/1/201715Exploit
- http://www.securityfocus.com/bid/3142Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6944
- http://www.kb.cert.org/vuls/id/314347US Government Resource
- http://www.securityfocus.com/archive/1/201715Exploit
- http://www.securityfocus.com/bid/3142Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6944
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.