Vulnerability Description
wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for wwwthreads forums.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wired Community Software | Wwwthreads | All versions |
References
- http://www.securityfocus.com/bid/967
- http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.10.100
- http://www.securityfocus.com/bid/967
- http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.10.100
FAQ
What is CVE-2000-0125?
CVE-2000-0125 is a vulnerability with a CVSS score of 7.5 (HIGH). wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for wwwthreads forums.
How severe is CVE-2000-0125?
CVE-2000-0125 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0125?
Check the references section above for vendor advisories and patch information. Affected products include: Wired Community Software Wwwthreads.