CVE-2004-0338: SQL Injection
Published Mar 18, 2004
·Updated
SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.
Affected Software
8 affected components
Invision Power Services Invision Board=2.0_pdr3
Invision Power Services Invision Board=1.3
Invision Power Services Invision Board=1.1.1
Invision Power Services Invision Board=1.2
Invision Power Services Invision Board=1.0
Invision Power Services Invision Board=2.0_alpha_3
Invision Power Services Invision Board=1.1.2
Invision Power Services Invision Board=1.0.1
Event History
Mar 18, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0338?
CVE-2004-0338 is considered a moderate severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2004-0338?
To fix CVE-2004-0338, you should upgrade to a patched version of Invision Board that addresses the SQL injection vulnerability.
3
Which versions of Invision Board are affected by CVE-2004-0338?
Versions 1.0, 1.1, 1.2, 1.3, 2.0 alpha 3, and 2.0_pdr3 of Invision Board are affected by CVE-2004-0338.
4
What type of vulnerability is CVE-2004-0338?
CVE-2004-0338 is categorized as an SQL injection vulnerability.
5
Can CVE-2004-0338 lead to unauthorized access?
Yes, CVE-2004-0338 can allow attackers to execute arbitrary SQL queries, potentially leading to unauthorized access to database information.