PT-2005-1617 · Punbb · Punbb

John Gumbel

·

Published

2005-02-27

·

Updated

2017-07-11

·

CVE-2005-0569

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PunBB version 1.2.1
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via several parameters, including the language parameter to "register.php", the change email feature in "profile.php", or the posts or topics parameter to "moderate.php".
Recommendations For PunBB version 1.2.1, consider restricting access to the "register.php", "profile.php", and "moderate.php" scripts until a patch is available. As a temporary workaround, avoid using the language, posts, and topics parameters in the affected scripts.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0569

Affected Products

Punbb