SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSir Gnuboard
APPSir≤ 5.3.2.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
Related vulnerabilities
CVE-2005-0269CRITICAL9.8PL ✓same product
GNUBoard: bypass weryfikacji rozszerzenia pliku przez wielkie litery
CVE-2024-41475HIGH8.8same product
Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
CVE-2022-44216HIGH7.5same product
Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users w...
CVE-2022-1252HIGH8.2same product
Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and includin...
CVE-2011-4066HIGH7.5same product
SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute a...