CVE-2005-4259
ASPBB 0.4 - SQL Injection via TID, FORUM_ID, or PROFILE_ID Parameters
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2005-4259. PoCs published by Dj_Eyes.
AI-analyzed exploit summary The code describes SQL injection vulnerabilities in ASPBB due to unsanitized user input in the TID parameter of topic.asp. Exploitation could lead to data compromise or underlying database attacks.
Description
Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.
Exploits (3)
The code describes SQL injection vulnerabilities in ASPBB due to unsanitized user input in the TID parameter of topic.asp. Exploitation could lead to data compromise or underlying database attacks.
The provided text describes SQL injection vulnerabilities in ASPBB due to improper input sanitization. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.
The provided text describes a SQL injection vulnerability in ASPBB, where the 'FORUM_ID' parameter in 'forum.asp' is not properly sanitized. It references a SecurityFocus advisory but does not include actual exploit code.