CVE-2011-5137
tForum b0.915 - SQL Injection via TopicID, BoardID, or CatID Parameter
Title source: llmDescription
Multiple SQL injection vulnerabilities in tForum b0.915 allow remote attackers to execute arbitrary SQL commands via the (1) TopicID parameter to viewtopic.php, the (2) BoardID parameter to viewboard.php, or (3) CatID parameter to viewcat.php.
References (2)
Core 2
Core References
Exploit x_refsource_misc
http://packetstormsecurity.org/files/view/108184/tforum-sqlxss.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/71975
Scores
EPSS
0.0120
EPSS Percentile
65.0%
Details
CWE
CWE-89
Status
published
Products (1)
tforum/tforum
b0.915
Published
Aug 31, 2012
Tracked Since
Feb 18, 2026