CVE-2005-4259

ASPBB 0.4 - SQL Injection via TID, FORUM_ID, or PROFILE_ID Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2005-4259. PoCs published by Dj_Eyes.

AI-analyzed exploit summary The code describes SQL injection vulnerabilities in ASPBB due to unsanitized user input in the TID parameter of topic.asp. Exploitation could lead to data compromise or underlying database attacks.

Description

Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.

Exploits (3)

exploitdb WRITEUP VERIFIED
by Dj_Eyes · textwebappsasp
https://www.exploit-db.com/exploits/26821

The code describes SQL injection vulnerabilities in ASPBB due to unsanitized user input in the TID parameter of topic.asp. Exploitation could lead to data compromise or underlying database attacks.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: ASPBB (version not specified)
No auth needed
Prerequisites: Access to the vulnerable ASPBB application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Dj_Eyes · textwebappsasp
https://www.exploit-db.com/exploits/26823

The provided text describes SQL injection vulnerabilities in ASPBB due to improper input sanitization. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: ASPBB (version not specified)
No auth needed
Prerequisites: Access to the vulnerable ASPBB application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Dj_Eyes · textwebappsasp
https://www.exploit-db.com/exploits/26822

The provided text describes a SQL injection vulnerability in ASPBB, where the 'FORUM_ID' parameter in 'forum.asp' is not properly sanitized. It references a SecurityFocus advisory but does not include actual exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: ASPBB (version not specified)
No auth needed
Prerequisites: Access to the vulnerable ASPBB forum page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15859
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/40004

Scores

EPSS 0.0107
EPSS Percentile 60.4%

Details

Status published
Products (1)
aspbb/aspbb 0.4
Published Dec 15, 2005
Tracked Since Feb 18, 2026