Vulnerability Description
Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to dlman.php in DLMan Pro or (2) id parameter to links.php in Linkz Pro (aka LinksLinks Pro).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlman Pro | Dlman Pro | 0.9.8 |
| Linkz Pro | Linkz Pro | 1.0.3_beta2 |
References
- http://marc.info/?l=bugtraq&m=111271895819594&w=2
- http://marc.info/?l=bugtraq&m=111272430128195&w=2
- http://www.securityfocus.com/bid/13028Exploit
- http://www.securityfocus.com/bid/13030Exploit
- http://www.snailsource.com/forum/dlman.php?func=file_info&file_id=77
- http://marc.info/?l=bugtraq&m=111271895819594&w=2
- http://marc.info/?l=bugtraq&m=111272430128195&w=2
- http://www.securityfocus.com/bid/13028Exploit
- http://www.securityfocus.com/bid/13030Exploit
- http://www.snailsource.com/forum/dlman.php?func=file_info&file_id=77
FAQ
What is CVE-2005-1026?
CVE-2005-1026 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to dlman.php in DLMan Pro or (2) id parame...
How severe is CVE-2005-1026?
CVE-2005-1026 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-1026?
Check the references section above for vendor advisories and patch information. Affected products include: Dlman Pro Dlman Pro, Linkz Pro Linkz Pro.