← Back

CVE-2008-4431

nvd nist
Published: Oct 3, 2008Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

SQL injection vulnerability in index.php in IceBB 1.0-rc9.3 and earlier allows remote attackers to execute arbitrary SQL commands via the skin parameter, probably related to an incorrect protection mechanism in the clean_string function in includes/functions.php.

Affected (15)

Products: Icebb: Icebb
1 product
Icebb
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Icebb
Up to 1.0
Version 0.9.1
Version 0.9.2.1
Version 0.9.2
Version 0.9.3.1
Version 0.9.3
Version 0.9 rc1
Version 1.0 rc5.1
Version 1.0 rc5
Version 1.0 rc6
Version 1.0 rc7
Version 1.0 rc8
Version 1.0 rc9.1
Version 1.0 rc9.2
Version 1.0 rc9

References (8)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.