HIGH🇵🇱 Wersja polska

CVE-2011-4066

CVSS 7.5v2.0pub. 2011-11-04upd. 2026-04-29

SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
  • Sir Gnuboard

    APP
    Sir
    3.303.313.323.333.343.353.363.373.383.393.404.31.03≤ 4.33.02
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2020-18662CRITICAL9.8PL ✓same product

SQL Injection w gnuboard5 przez parametr table_prefix w install_db.php

CVE-2005-0269CRITICAL9.8PL ✓same product

GNUBoard: bypass weryfikacji rozszerzenia pliku przez wielkie litery

CVE-2024-41475HIGH8.8same product

Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

CVE-2022-44216HIGH7.5same product

Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users w...

CVE-2022-1252HIGH8.2same product

Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and includin...