Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to member.asp, (2) forum parameter to forum.asp, or (3) various parameters in register.asp.
References
Configurations
History
20 Nov 2024, 23:56
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=111428133317901&w=2 - | |
References | () http://secunia.com/advisories/15072 - | |
References | () http://securitytracker.com/id?1013793 - Exploit | |
References | () http://www.digitalparadox.org/advisories/bkdev.txt - Exploit | |
References | () http://www.osvdb.org/15784 - | |
References | () http://www.osvdb.org/15785 - | |
References | () http://www.osvdb.org/15786 - | |
References | () http://www.securityfocus.com/archive/1/431659/100/0/threaded - | |
References | () http://www.securityfocus.com/archive/1/431863/100/0/threaded - |
Information
Published : 2005-04-23 04:00
Updated : 2024-11-20 23:56
NVD link : CVE-2005-1287
Mitre link : CVE-2005-1287
CVE.ORG link : CVE-2005-1287
JSON object : View
Products Affected
bk_dev
- bk_forum
CWE