CVE-2005-3686

Unclassified Newsboard < 1.5.3_patch3 - SQL Injection

Title source: rule

Description

SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1319

Scores

EPSS 0.0123
EPSS Percentile 79.2%

Details

CWE
CWE-89
Status published
Products (1)
newsboard/unclassified_newsboard < 1.5.3_patch3
Published Nov 19, 2005
Tracked Since Feb 18, 2026