CVE-2003-0486: SQL Injection
Published Jun 28, 2003
·Updated
SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topicid parameter.
Affected Software
1 affected component
Phpbb Group Phpbb<=2.0.5
Remediation
Patch Available
Patch Available
Event History
Jun 28, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 7, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0486?
CVE-2003-0486 is considered a medium severity vulnerability due to the potential for remote attackers to steal sensitive password hashes.
2
How do I fix CVE-2003-0486?
To fix CVE-2003-0486, upgrade phpBB to version 2.0.6 or later, which addresses the SQL injection vulnerability.
3
What versions of phpBB are affected by CVE-2003-0486?
CVE-2003-0486 affects phpBB versions 2.0.5 and earlier.
4
What type of vulnerability is CVE-2003-0486?
CVE-2003-0486 is an SQL injection vulnerability that allows attackers to manipulate database queries.
5
Can CVE-2003-0486 lead to further attacks?
Yes, CVE-2003-0486 can potentially lead to further attacks, including unauthorized access to user accounts and data breaches.