CVE-2002-1505: SQL Injection
Published Apr 2, 2003
·Updated
SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter.
Affected Software
4 affected components
WoltLab Burning Board<=2.0_rc1
WoltLab Burning Board=2.0_beta_3
WoltLab Burning Board=2.0_beta_4
WoltLab Burning Board=2.0_beta_5
Remediation
Event History
Apr 2, 2003
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1505?
CVE-2002-1505 is considered a high severity vulnerability due to its potential for remote exploitation and database modification.
2
How do I fix CVE-2002-1505?
To fix CVE-2002-1505, upgrade to a version of WoltLab Burning Board later than 2.0 RC 1.
3
Who is affected by CVE-2002-1505?
CVE-2002-1505 affects all versions of WoltLab Burning Board up to and including 2.0 RC 1.
4
What type of vulnerability is CVE-2002-1505?
CVE-2002-1505 is an SQL injection vulnerability that allows attackers to modify the database.
5
What parameter is exploited in CVE-2002-1505?
CVE-2002-1505 exploits the 'boardid' parameter in the board.php file.