CVE-2005-3364
Multiple SQL injection vulnerabilities in DboardGear allow remote attackers to execute arbitrary SQL commands via (1) the buddy parameter in buddy.php, (2) the u2uid parameter in u2u.php, and (3) an invalid theme file in the themes action to ctrtools.php.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in DboardGear allow remote attackers to execute arbitrary SQL commands via (1) the buddy parameter in buddy.php, (2) the u2uid parameter in u2u.php, and (3) an invalid theme file in the themes action to ctrtools.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- platinum/dboardgear
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=113017087231116&w=2
- http://securityreason.com/securityalert/109
- http://securitytracker.com/id?1015095Exploit
- http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-10/0298.htmlExploit
- http://www.osvdb.org/20442
- http://www.osvdb.org/20443
- http://www.securityfocus.com/bid/15174Vendor Advisory
- http://www.securityfocus.com/bid/15194
- http://marc.info/?l=bugtraq&m=113017087231116&w=2
- http://securityreason.com/securityalert/109
- http://securitytracker.com/id?1015095Exploit
- http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-10/0298.htmlExploit
- http://www.osvdb.org/20442
- http://www.osvdb.org/20443
- http://www.securityfocus.com/bid/15174Vendor Advisory
- http://www.securityfocus.com/bid/15194
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.