Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2005-02-14T05:00:00
Updated: 2024-08-07T21:13:53.791Z
Reserved: 2005-02-14T00:00:00
Link: CVE-2005-0413

No data.

Status : Modified
Published: 2005-04-27T04:00:00.000
Modified: 2024-11-20T23:55:04.050
Link: CVE-2005-0413

No data.