← Back

CVE-2005-2193

nvd nist
Published: Jul 11, 2005Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the array from being properly escaped.

Affected (18)

Products: Punbb: Punbb
1 product
Punbb
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Punbb
Version 1.0.1
Version 1.0
Version 1.0_alpha
Version 1.0_beta1
Version 1.0_beta2
Version 1.0_beta3
Version 1.0_rc1
Version 1.0_rc2
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1
Version 1.2.1
Version 1.2.2
Version 1.2.3
Version 1.2.4

References (6)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.