CVE-2005-3259

Versatilebulletinboard - SQL Injection

Title source: rule

Description

Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) "search this thread" feature, (3) "search for posts" feature, (4) "forgot password" feature, (5) list parameter in userlistpre.php, and the (6) select, (7) categ, and (8) to parameters in index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1245

Scores

EPSS 0.0458
EPSS Percentile 89.2%

Details

Status published
Products (1)
versatilebulletinboard/versatilebulletinboard 1.0.0.rc2
Published Oct 20, 2005
Tracked Since Feb 18, 2026