CVE-2001-1482: SQL Injection
Published Dec 31, 2001
·Updated
SQL injection vulnerability in bbmemberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable.
Affected Software
1 affected component
Phpbb Group Phpbb=1.4.2
Event History
Dec 31, 2001
CVE Published
05:00 AM
Jun 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1482?
CVE-2001-1482 has a moderate severity due to the potential for remote SQL injection attacks.
2
How do I fix CVE-2001-1482?
To fix CVE-2001-1482, update phpBB to a version that is not vulnerable, preferably a version higher than 1.4.2.
3
What types of attacks can be executed using CVE-2001-1482?
CVE-2001-1482 allows attackers to execute arbitrary SQL queries, potentially leading to data exposure or corruption.
4
Which version of phpBB is affected by CVE-2001-1482?
CVE-2001-1482 specifically affects phpBB version 1.4.2.
5
Is CVE-2001-1482 still a relevant vulnerability?
While CVE-2001-1482 is an older vulnerability, it remains relevant for systems that have not been updated or are still running vulnerable versions.