CVE-2004-0323 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php (2) desc parameter in misc.php (3) tpp parameter in forumdisplay.php (4) ascdesc parameter in forumdisplay.php or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta.
Reference
http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html http://archives.neohapsis.com/archives/bugtraq/2004-03/0265.html http://marc.info/?l=bugtraq&m=107756526625179&w=2 http://www.securityfocus.com/bid/9726 http://www.xmbforum.com/community/boards/viewthread.php?tid=746859 https://exchange.xforce.ibmcloud.com/vulnerabilities/15295
Share on: