Vulnerability Description
SQL injection vulnerability in the favorites module in index.php in IPBProArcade 2.5.2 allows remote attackers to inject arbitrary SQL commands via the gameid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. In addition, the demonstration code as used by third parties suggests that this might be a different type of vulnerability related to shell metacharacters. Finally, this could be a rediscovery of CVE-2004-1430.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ipbproarcade | Ipbproarcade | 2.5.2 |
References
FAQ
What is CVE-2005-4702?
CVE-2005-4702 is a vulnerability with a CVSS score of 6.4 (MEDIUM). SQL injection vulnerability in the favorites module in index.php in IPBProArcade 2.5.2 allows remote attackers to inject arbitrary SQL commands via the gameid parameter. NOTE: the provenance of this ...
How severe is CVE-2005-4702?
CVE-2005-4702 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-4702?
Check the references section above for vendor advisories and patch information. Affected products include: Ipbproarcade Ipbproarcade.