CVE-2005-3364
Last modified
CVE-2005-3364 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in DboardGear allow remote attackers to execute arbitrary SQL commands via (1) the buddy parameter in buddy.php, (2) the u2uid parameter in u2u.php, and (3) an invalid theme file in the themes action to ctrtools.php.. EPSS estimates a 1.55% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in DboardGear allow remote attackers to execute arbitrary SQL commands via (1) the buddy parameter in buddy.php, (2) the u2uid parameter in u2u.php, and (3) an invalid theme file in the themes action to ctrtools.php.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Platinum | Dboardgear | All versions |
References
- http://www.securityfocus.com/bid/15174Vendor Advisory
- http://www.securityfocus.com/bid/15174Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3364?
How severe is CVE-2005-3364?
How do I fix CVE-2005-3364?
Are you affected by CVE-2005-3364?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
