CVE-2004-1515: SQL Injection
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1515?
CVE-2004-1515 is considered a high severity vulnerability due to its potential to allow arbitrary SQL statements to be executed by remote attackers.
How do I fix CVE-2004-1515?
To fix CVE-2004-1515, upgrade to a patched version of vBulletin that addresses this SQL injection vulnerability.
What are the affected versions in CVE-2004-1515?
CVE-2004-1515 affects vBulletin versions 3.0.0 through 3.0.6, including beta and release candidates.
Can CVE-2004-1515 allow data theft?
Yes, CVE-2004-1515 can enable attackers to execute arbitrary SQL queries which may lead to data theft.
How can I determine if my vBulletin installation is vulnerable to CVE-2004-1515?
Check if your vBulletin version is between 3.0.0 and 3.0.6, as those versions are vulnerable to CVE-2004-1515.