CVE-2004-2695: SQL Injection
SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL statements via the xinvoicenum parameter. NOTE: this issue might be related to CVE-2006-4267.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2695?
CVE-2004-2695 has a moderate severity rating due to the potential for remote SQL injection attacks.
How do I fix CVE-2004-2695?
To fix CVE-2004-2695, upgrade to a version of vBulletin later than 3.0.3, which includes patches for this vulnerability.
Which versions of vBulletin are affected by CVE-2004-2695?
CVE-2004-2695 affects vBulletin versions 3.0 through 3.0.3, along with several beta releases.
Can CVE-2004-2695 be exploited remotely?
Yes, CVE-2004-2695 can be exploited remotely by attackers through the x_invoice_num parameter.
Is CVE-2004-2695 related to any other vulnerabilities?
CVE-2004-2695 may be related to CVE-2006-4267, which also involves SQL injection in vBulletin.