← Back

CVE-2004-0323

nvd nist
Published: Dec 31, 2004Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta.

Affected (3)

Products: Xmb Forum: Xmb
1 product
Xmb
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Xmb Forum
Version 1.8
Version 1.8_sp1
Version 1.8_sp2

Timeline

No history available yet.