CVE-2004-1864

critical

Description

SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/15655

https://docs.xmbforum2.com/index.php?title=Security_Issue_History

http://www.securityfocus.com/bid/9983

http://www.osvdb.org/16886

http://securitytracker.com/id?1009561

http://marc.info/?l=bugtraq&m=108032355905265&w=2

Details

Source: Mitre, NVD

Published: 2004-03-26

Updated: 2024-11-20

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical