CVE-2011-5137

tForum b0.915 - SQL Injection via TopicID, BoardID, or CatID Parameter

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in tForum b0.915 allow remote attackers to execute arbitrary SQL commands via the (1) TopicID parameter to viewtopic.php, the (2) BoardID parameter to viewboard.php, or (3) CatID parameter to viewcat.php.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/71975

Scores

EPSS 0.0120
EPSS Percentile 65.0%

Details

CWE
CWE-89
Status published
Products (1)
tforum/tforum b0.915
Published Aug 31, 2012
Tracked Since Feb 18, 2026