Vulnerability Description
Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywords parameter to search.asp, (2) handle parameter to profile.asp, (3) txtUserHandle parameter to reg2.asp or (4) txtUserEmail parameter to forgot.asp.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadboard Instant | Asp Message Board | All versions |
References
- http://marc.info/?l=bugtraq&m=109630777608244&w=2
- http://secunia.com/advisories/12658Vendor Advisory
- http://securitytracker.com/id?1011419
- http://www.securityfocus.com/bid/11250Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17498
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17500
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17501
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17502
- http://marc.info/?l=bugtraq&m=109630777608244&w=2
- http://secunia.com/advisories/12658Vendor Advisory
- http://securitytracker.com/id?1011419
- http://www.securityfocus.com/bid/11250Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17498
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17500
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17501
FAQ
What is CVE-2004-1555?
CVE-2004-1555 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywords parameter to search.asp, (2) handle parameter t...
How severe is CVE-2004-1555?
CVE-2004-1555 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1555?
Check the references section above for vendor advisories and patch information. Affected products include: Broadboard Instant Asp Message Board.