CVE-2008-6970

UnknownEPSS 7.25%

Last modified

CVE-2008-6970 is a vulnerability of currently unknown severity. SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.. EPSS estimates a 7.25% chance of exploitation in the next 30 days.

Description

SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.

Metrics

EPSS Probability
7.25%

93.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
UbbcentralUbb.Threads<= 7.3.1
UbbcentralUbb.Threads3.4
UbbcentralUbb.Threads3.5
UbbcentralUbb.Threads5.0
UbbcentralUbb.Threads5.5.1
UbbcentralUbb.Threads6.0
UbbcentralUbb.Threads6.0.1
UbbcentralUbb.Threads6.0.2
UbbcentralUbb.Threads6.0.3
UbbcentralUbb.Threads6.1
UbbcentralUbb.Threads6.1.1
UbbcentralUbb.Threads6.2
UbbcentralUbb.Threads6.2.1
UbbcentralUbb.Threads6.2.2
UbbcentralUbb.Threads6.2.3
UbbcentralUbb.Threads6.3
UbbcentralUbb.Threads6.3.1
UbbcentralUbb.Threads6.4
UbbcentralUbb.Threads6.4.1
UbbcentralUbb.Threads6.4.2
UbbcentralUbb.Threads6.4.3
UbbcentralUbb.Threads6.4.4
UbbcentralUbb.Threads6.5
UbbcentralUbb.Threads6.5.1
UbbcentralUbb.Threads6.5.1.1
UbbcentralUbb.Threads6.5.2
UbbcentralUbb.Threads6.5.2_beta2
UbbcentralUbb.Threads6.5.3
UbbcentralUbb.Threads7.0
UbbcentralUbb.Threads7.1
UbbcentralUbb.Threads7.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-6970?
SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.
How severe is CVE-2008-6970?
Severity scoring for CVE-2008-6970 is pending analysis. The EPSS model estimates a 7.25% probability of exploitation in the next 30 days.
How do I fix CVE-2008-6970?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-6970?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST