First published: Mon Dec 31 2001(Updated: )
SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpbb Group Phpbb | =1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1482 has a moderate severity due to the potential for remote SQL injection attacks.
To fix CVE-2001-1482, update phpBB to a version that is not vulnerable, preferably a version higher than 1.4.2.
CVE-2001-1482 allows attackers to execute arbitrary SQL queries, potentially leading to data exposure or corruption.
CVE-2001-1482 specifically affects phpBB version 1.4.2.
While CVE-2001-1482 is an older vulnerability, it remains relevant for systems that have not been updated or are still running vulnerable versions.