VulnerabilityModified
CVE-2004-1588
SQL injection vulnerability in GoSmart Message Board allows remote attackers to execute arbitrary SQL code via the (1) QuestionNumber and Category parameters to Forum.asp or (2) Username and Password parameter to Login_Exec.asp.
HIGH 7.5EPSS 1.33%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in GoSmart Message Board allows remote attackers to execute arbitrary SQL code via the (1) QuestionNumber and Category parameters to Forum.asp or (2) Username and Password parameter to Login_Exec.asp.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.33% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- gosmart/gosmart message board
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109751522823011&w=2
- http://secunia.com/advisories/12790/Vendor Advisory
- http://www.securityfocus.com/bid/11361Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17678
- http://marc.info/?l=bugtraq&m=109751522823011&w=2
- http://secunia.com/advisories/12790/Vendor Advisory
- http://www.securityfocus.com/bid/11361Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17678
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.