CVE-2006-4025

Loading...

General

Score:7.5/10.0
Severity:High
Category:N/A
Exploit:Available

Impact Metrics

Confidentiality:Partial
Integrity:Partial
Availability:Partial

Exploitability Metrics

Access Vector:Network
Access Complexity:Low
Authentication:None

Published on 09/08/06 - Updated on 17/10/18

Description

SQL injection vulnerability in profile.php in XennoBB 2.1.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) bday_day, (2) bday_month, and (3) bday_year parameters in the personal section.

Category:

There is insufficient information about the issue to classify it; details are unknown or unspecified.

Security Notices

US National Vulnerability DatabaseCVE-2006-4025

Exploits

Exploit-DBEDB-28347
SecurityFocusBID-19374

Relative technologies

VendorProduct
xennobbxennobb

Share this vulnerability with:

Twitter Facebook LinkedIn Mail