CVE-2005-2058

Ubbcentral Ubb.threads - SQL Injection

Title source: rule

Description

Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.

Exploits (8)

exploitdb WORKING POC VERIFIED
by mh_p0rtal · phpwebappsphp
https://www.exploit-db.com/exploits/1069
exploitdb WORKING POC VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25900
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25902
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25899
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25903
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25897
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25898
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25901

Scores

EPSS 0.0054
EPSS Percentile 67.7%

Details

Status published
Products (20)
ubbcentral/ubb.threads 6.0
ubbcentral/ubb.threads 6.0.1
ubbcentral/ubb.threads 6.0.2
ubbcentral/ubb.threads 6.0.3
ubbcentral/ubb.threads 6.1
ubbcentral/ubb.threads 6.1.1
ubbcentral/ubb.threads 6.2
ubbcentral/ubb.threads 6.2.1
ubbcentral/ubb.threads 6.2.2
ubbcentral/ubb.threads 6.2.3
... and 10 more
Published Jun 29, 2005
Tracked Since Feb 18, 2026